LIVE · cybersecurity feed
Live wire
nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

zeroday.news ·

Suspected Russian cyber espionage groups have been observed exploiting legitimate Google OAuth and WhatsApp linking mechanisms to compromise accounts belonging to individuals in sensitive sectors. The activity targets individuals in academia, aerospace and defense, government, and think tanks across Europe, as well as academia and think tanks in the United States. Three distinct threat clusters, identified as UNC6293, UNC7005, and UNC5976, are reportedly involved in these persistent and adaptive campaigns.

The reported attacks leverage legitimate authentication flows, indicating a sophisticated approach that bypasses traditional credential theft methods. In the case of Google OAuth, attackers likely manipulate the consent process, tricking users into granting malicious applications access to their Google account data. This could involve phishing campaigns that present seemingly legitimate requests for OAuth authorization, leading users to unwittingly approve access for an attacker-controlled application. Once authorized, the malicious application can access various data and services depending on the scope of the granted permissions, potentially including emails, contacts, and calendar information.

The abuse of WhatsApp linking suggests a different vector, possibly involving social engineering to link a victim's WhatsApp account to an attacker-controlled device. WhatsApp's multi-device feature allows users to link their account to several companion devices, such as web browsers or desktop applications. An attacker could potentially trick a user into scanning a QR code that, instead of linking to their own legitimate device, links their account to a device controlled by the attacker, thereby gaining access to their messages and contacts.

The affected sectors — academia, aerospace and defense, government, and think tanks — are common targets for state-sponsored espionage due to their access to sensitive research, policy information, and strategic intelligence. The geographic scope, encompassing Europe and the U.S., aligns with typical geopolitical interests of suspected Russian state-sponsored actors. The identification of specific threat clusters (UNC6293, UNC7005, and UNC5976) suggests ongoing tracking and attribution efforts by security researchers.

Mitigation for these types of attacks typically involves enhanced user awareness and robust authentication practices. Users should be highly suspicious of unsolicited requests to link accounts or grant application permissions, even if they appear to originate from legitimate services. Organizations should implement strong multi-factor authentication (MFA) for all accounts, which can significantly reduce the risk of account compromise even if initial credentials or OAuth tokens are stolen. Regular security awareness training, emphasizing the dangers of phishing and social engineering tactics, is also crucial.

For Google OAuth, users should regularly review and revoke permissions for any unfamiliar or suspicious applications connected to their Google account. For WhatsApp, users should be extremely cautious about scanning QR codes for linking purposes and should regularly review linked devices within their WhatsApp settings, unlinking any unrecognized devices. Organizations should also consider implementing endpoint detection and response (EDR) solutions to detect unusual activity that might indicate a compromised account or device.

This incident underscores a broader trend in cyber espionage where threat actors increasingly abuse legitimate functionalities and trust relationships to achieve their objectives. Rather than relying solely on zero-day exploits or brute-force attacks, sophisticated groups are adapting their tactics to exploit the inherent trust in widely used platforms and authentication mechanisms. This shift necessitates a defense-in-depth strategy that combines technical controls with continuous user education and vigilance against evolving social engineering techniques.

nation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

malware

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.

security

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.

security

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.

malwarehigh

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]