Three suspected Russian cyber-espionage groups have been observed employing OAuth abuse in targeted phishing campaigns against individuals in academia, aerospace, defense, government agencies, and think tanks across Europe and the United States. These highly focused operations, which have been ongoing since at least last year, involve fewer than 100 targets per campaign and typically result in fewer than 10 victims. The adoption of OAuth abuse makes these social engineering tactics appear more legitimate, allowing attackers to compromise personal accounts across multiple platforms and making phishing attempts harder to recognize.
One of the groups, UNC6293, has been tracked for nearly two years and is believed to be associated with APT29, also known as Cozy Bear or Ice Relic, which is often linked to Russia's Foreign Intelligence Service (SVR). UNC6293 has been impersonating US State Department employees to trick victims into granting long-term access to their email. While previously observed phishing for application passwords from critics of Russia, the group added OAuth phishing to its toolkit in June 2026. This involved requesting targets to share either a full URL or a "verification code" after a legitimate login to an external provider, which would then grant UNC6293 account access.
Another group, UNC7005, first identified in February, is also assessed with moderate confidence to be connected to APT29/Cozy Bear/Ice Relic and the SVR. This group primarily targets academic, diplomatic, and nonprofit personnel in Ukraine, Western Europe, and the US. While sharing similarities with UNC6293, it is tracked separately due to its lower sophistication, poorer operational security, divergent infrastructure, and use of malware. UNC7005 has engaged in device-code phishing for both Microsoft and WhatsApp accounts.
In May and June, UNC7005 conducted social engineering attacks spoofing WhatsApp, prompting victims to join a voice call, encrypted chat, or download a file. Joining the voice call activated malicious JavaScript that recorded audio and video, uploading it to the attacker's command-and-control server. The group also carried out a broader phishing wave in May, targeting academics, diplomats, and researchers focused on Russia and former Soviet states. This involved elaborately built websites, including one spoofing the GLOBSEC forum, which offered a "Summit Companion App" that, when downloaded, installed infostealers on macOS and Windows devices. Since August, UNC7005 has also initiated Google and Microsoft account OAuth phishing operations using cloud infrastructure.
UNC7005 has also been observed compromising captive portal networks to deliver information stealers, keyloggers, and other malware. These operations, which began in February, targeted users of public Wi-Fi networks in hospitality venues like hotels and conference centers, utilizing AI assistance. Phishing lures often appear as invitations to diplomatic events and conferences, delivered via email with links to attacker-controlled websites. These sites frequently reuse templates, such as one from an "embassy invite" operation, and include detailed registration processes, sometimes even featuring an "epicurean wine selection" theme seen in previous Ice Relic-linked campaigns.
The third group, UNC5976, is another suspected Russian cyberespionage entity that specializes in stealing OAuth tokens. GTIG began tracking its OAuth-related activities in March 2026. UNC5976 acquires multiple file-sharing related domains and creates associated cloud projects. These domains host fake file-sharing pages that prompt users to "Continue with Google" via a popup link. This link directs victims to a legitimate Google OAuth login page, and after authentication, redirects them to a Google Cloud project URL that saves the authentication token for the attacker.
UNC5976 is considered distinct from the other two initial access groups, suggesting potentially different strategic mandates and alignment with alternative Russian intelligence services. This group also employs dedicated infrastructure for post-compromise activities, rather than residential proxies, and incorporates more malware and tooling in its OAuth operations. Google's Threat Intelligence Group (GTIG) has emphasized raising awareness about these campaigns to help potential targets recognize malicious outreach.






