LIVE · cybersecurity feed
Live wire
phishing

Russian snoops add OAuth abuse to targeted phishing campaigns

Don't click on that State Department meeting invite

zeroday.news ·

Three suspected Russian cyber-espionage groups have been observed employing OAuth abuse in targeted phishing campaigns against individuals in academia, aerospace, defense, government agencies, and think tanks across Europe and the United States. These highly focused operations, which have been ongoing since at least last year, involve fewer than 100 targets per campaign and typically result in fewer than 10 victims. The adoption of OAuth abuse makes these social engineering tactics appear more legitimate, allowing attackers to compromise personal accounts across multiple platforms and making phishing attempts harder to recognize.

One of the groups, UNC6293, has been tracked for nearly two years and is believed to be associated with APT29, also known as Cozy Bear or Ice Relic, which is often linked to Russia's Foreign Intelligence Service (SVR). UNC6293 has been impersonating US State Department employees to trick victims into granting long-term access to their email. While previously observed phishing for application passwords from critics of Russia, the group added OAuth phishing to its toolkit in June 2026. This involved requesting targets to share either a full URL or a "verification code" after a legitimate login to an external provider, which would then grant UNC6293 account access.

Another group, UNC7005, first identified in February, is also assessed with moderate confidence to be connected to APT29/Cozy Bear/Ice Relic and the SVR. This group primarily targets academic, diplomatic, and nonprofit personnel in Ukraine, Western Europe, and the US. While sharing similarities with UNC6293, it is tracked separately due to its lower sophistication, poorer operational security, divergent infrastructure, and use of malware. UNC7005 has engaged in device-code phishing for both Microsoft and WhatsApp accounts.

In May and June, UNC7005 conducted social engineering attacks spoofing WhatsApp, prompting victims to join a voice call, encrypted chat, or download a file. Joining the voice call activated malicious JavaScript that recorded audio and video, uploading it to the attacker's command-and-control server. The group also carried out a broader phishing wave in May, targeting academics, diplomats, and researchers focused on Russia and former Soviet states. This involved elaborately built websites, including one spoofing the GLOBSEC forum, which offered a "Summit Companion App" that, when downloaded, installed infostealers on macOS and Windows devices. Since August, UNC7005 has also initiated Google and Microsoft account OAuth phishing operations using cloud infrastructure.

UNC7005 has also been observed compromising captive portal networks to deliver information stealers, keyloggers, and other malware. These operations, which began in February, targeted users of public Wi-Fi networks in hospitality venues like hotels and conference centers, utilizing AI assistance. Phishing lures often appear as invitations to diplomatic events and conferences, delivered via email with links to attacker-controlled websites. These sites frequently reuse templates, such as one from an "embassy invite" operation, and include detailed registration processes, sometimes even featuring an "epicurean wine selection" theme seen in previous Ice Relic-linked campaigns.

The third group, UNC5976, is another suspected Russian cyberespionage entity that specializes in stealing OAuth tokens. GTIG began tracking its OAuth-related activities in March 2026. UNC5976 acquires multiple file-sharing related domains and creates associated cloud projects. These domains host fake file-sharing pages that prompt users to "Continue with Google" via a popup link. This link directs victims to a legitimate Google OAuth login page, and after authentication, redirects them to a Google Cloud project URL that saves the authentication token for the attacker.

UNC5976 is considered distinct from the other two initial access groups, suggesting potentially different strategic mandates and alignment with alternative Russian intelligence services. This group also employs dedicated infrastructure for post-compromise activities, rather than residential proxies, and incorporates more malware and tooling in its OAuth operations. Google's Threat Intelligence Group (GTIG) has emphasized raising awareness about these campaigns to help potential targets recognize malicious outreach.

phishing
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)

In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#;x26;#;39;s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ... This is that method. Also, remember when we discussed yesterday about the beta graph commands in the Microsoft.Graph.Beta library? We&#;x26;#;39;ll u

security

Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise. One log that really bears looking at is the log of successful and failed logins. the call for that is:

security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

malware

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.