Skip to main content

Russian Threat Clusters Target Academia and Government via Auth Abuse

3 min read Runtime Rebel Intel
Primary source: cloud.google.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Immediate impact: Individuals in academia, aerospace, defense, government, and think tanks are targeted by Russian espionage operations.
  • Affected systems: Personal accounts across multiple platforms, Microsoft accounts, and WhatsApp via abused authentication workflows.
  • Remediation: Monitor for abnormal app password generation and educate users on recognizing sophisticated social engineering and OAuth prompts.

Advertisement

Overview of Russian Espionage Clusters

Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters that abuse legitimate authentication flows to target individuals working in academia, aerospace and defense, governments, and think tanks across Europe and the United States. While campaigns vary by group, they consistently focus on compromising personal and professional accounts by weaponizing standard authentication workflows.

The research details operations from APT29 sub-cluster UNC6293, alongside newly tracked clusters UNC7005 (also known as STORM-2945) and UNC5976. These threat actors execute persistent, adaptive phishing campaigns using social engineering themes centered on diplomatic events, conferences, and institutional meetings.

Technical Analysis of TTPs

Attackers increasingly bypass traditional multi-factor authentication (MFA) mechanisms by tricking users into completing legitimate authentication workflows on attacker-controlled infrastructure. This includes app password manipulation, OAuth token theft, and device code phishing.

UNC6293 App Password and OAuth Phishing

Assessed with moderate confidence as a sub-cluster of ICE RELIC (APT29), UNC6293 has run aggressive app password campaigns since mid-2025. App passwords grant secondary apps or devices permission to access an account without triggering standard 2FA checks.

  • Lure Mechanics: Attackers impersonated the U.S. State Department via PDF documents containing screenshots that instructed targets to create specific app passwords, such as ms.state.gov.
  • Evolution: In later campaigns, instead of asking victims to email the app password back, operators directed them to enter the generated credentials into authentication forms hosted on attacker-controlled, legitimate-looking websites.
  • OAuth Abuse: By June 2026, GTIG observed UNC6293 incorporating OAuth phishing by requesting targets to share authorization codes or full callback URLs after executing a genuine login with an external provider.

UNC7005 Device Code and Hospitality Redirects

UNC7005 shares targeting overlaps with UNC6293 but demonstrates lower operational security and incorporates malware deployment. Identified in early 2026, this cluster leverages unique tactics:

  • Targeted App Passwords: Unlike generic templates, UNC7005 constructs target-specific app passwords mapped directly to social engineering pretexts, such as secure file sharing workflows.
  • Device Code Phishing: The cluster targets Microsoft and WhatsApp accounts by sending emails disguised as diplomatic event invitations. Victims visiting attacker-controlled sites spoofing organizations like the GLOBSEC forum are prompted to input device codes, granting adversaries persistent access.
  • Captive Portal Abuse: UNC7005 is also tied to hospitality captive portal redirect vectors previously highlighted by Microsoft and ReliaQuest.

Defensive Recommendations

Defenders and high-risk personnel must adopt specific countermeasures to disrupt authentication abuse campaigns:

  • Audit App Passwords: Regularly review enterprise and personal tenant environments for unmonitored or legacy app password creations, restricting their generation where possible.
  • Monitor OAuth Grants: Implement strict visibility over third-party application permissions and OAuth consent grants to detect unauthorized token issuance.
  • User Awareness Training: Train high-risk individuals—such as diplomats, researchers, and government personnel—to recognize device code phishing prompts and abnormal authentication requests disguised as conference invitations.

Related: Zero-Click AI Browser Hacking Threatens Claude and ChatGPT Atlas, Hotel Wi-Fi Campaigns Use CornFlake and ChocoShell Malware

Advertisement

Advertisement