Overview of Russian Espionage Clusters
Recent intelligence published by the Google Threat Intelligence Group (GTIG) highlights three distinct suspected Russian threat clusters—UNC6293, UNC5976, and UNC7005—engaging in persistent and adaptive phishing campaigns. According to The Hacker News, these campaigns primarily target individuals working in academia, aerospace, defense, government sectors, and think tanks across Europe, Ukraine, Armenia, and the United States.
The activity underscores a broader shift among state-sponsored actors toward abusing legitimate cloud authentication mechanisms and platform features rather than relying solely on traditional malware payloads. By weaponizing trusted service flows, these adversaries bypass conventional security perimeters and trick users into willingly handing over access.
Technical Analysis of Attack Vectors
The identified threat clusters employ sophisticated social engineering themes, often impersonating diplomatic officials or using bespoke conference and event lures.
OAuth and Application Password Abuse
UNC6293, assessed as a sub-cluster of APT29 (also tracked as Cozy Bear or Midnight Blizzard), maintains a focus on low-volume, highly selective phishing. The group has historically utilized Google account application-specific passwords under diplomatic pretexts. More recently, the cluster has pivoted to OAuth token theft by tricking victims into sharing verification codes or full URLs after completing legitimate authentication steps.
Meanwhile, UNC5976 has automated token collection by deploying malicious cloud infrastructure behind file-sharing themed domains. Victims visiting these domains are presented with a fake login dialog featuring a legitimate “Continue with Google” prompt. Successful authentication redirects the user to a Google Cloud project hosting scripts that harvest the resulting authentication tokens. UNC5976 has also distributed a rogue Excel plugin codenamed HEADRUSH to deliver HTML Application loaders.
WhatsApp Device Linking and Device Code Phishing
UNC7005 (also known as Storm-2945) has introduced novel social engineering tactics, including spoofing WhatsApp to hijack messaging accounts. Attackers lure targets into linking their WhatsApp accounts with an attacker-controlled device under the guise of joining a secure voice call, encrypted chat, or document share. Once the user scans the legitimate QR linking code, the adversary gains full access to the messaging account and executes malicious JavaScript to capture audio and video feeds.
Additionally, UNC7005 employs device code phishing against Microsoft accounts. These campaigns utilize sophisticated lures involving diplomatic event invitations, including customized dining and wine preferences that mirror historical Ice Relic tactics tracked elsewhere as SPIKEDWINE.
Mitigations and Defense Guidance
Defending against authentication-abuse campaigns requires a multi-layered security posture that restricts reliance on easily phished credentials:
- Deploy Phishing-Resistant MFA: Transition away from SMS, push notifications, and basic app passwords toward FIDO2/WebAuthn-compliant hardware security keys which natively bind authentication to the legitimate origin.
- Audit OAuth Grants: Regularly review and restrict third-party application permissions across cloud tenant environments to detect unauthorized token generation and rogue cloud projects.
- Monitor Device Linking: Implement administrative alerts and visibility over corporate messaging and collaboration platforms for unexpected secondary device linking events.
Related: Hotel Wi-Fi Campaigns Use CornFlake and ChocoShell Malware, Identity Abuse and Phishing via Enterprise Collaboration Platforms