# Russian Threat Clusters Target Academia and Government via Auth Abuse

> Google Threat Intelligence Group tracks three Russian cyber espionage clusters abusing legitimate authentication flows and app passwords.

- Published: 2026-08-20T16:26:40.000Z
- Severity: medium
- Category: Threat Intel
- Tags: APT29, Phishing, Oauth Phishing, Credential Theft, Zero-Day
- Author: Runtime Rebel Intel
- Primary source: https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia/
- Canonical: https://runtimerebel.com/blog/russian-threat-clusters-target-academia-and-government-via-auth-abuse

## Key points

- Immediate impact: Individuals in academia, aerospace, defense, government, and think tanks are targeted by Russian espionage operations.
- Affected systems: Personal accounts across multiple platforms, Microsoft accounts, and WhatsApp via abused authentication workflows.
- Remediation: Monitor for abnormal app password generation and educate users on recognizing sophisticated social engineering and OAuth prompts.

## Overview of Russian Espionage Clusters

Google [Threat Intelligence](/glossary#threat-intelligence) Group ([GTIG](https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia/)) is tracking three distinct suspected Russian cyber espionage threat clusters that abuse legitimate authentication flows to target individuals working in academia, aerospace and defense, governments, and think tanks across Europe and the United States. While campaigns vary by group, they consistently focus on compromising personal and professional accounts by weaponizing standard authentication workflows.

The research details operations from [APT29](https://en.wikipedia.org/wiki/APT29) sub-cluster **UNC6293**, alongside newly tracked clusters **UNC7005** (also known as STORM-2945) and **UNC5976**. These threat actors execute persistent, adaptive [phishing](/glossary#phishing) campaigns using [social engineering](/glossary#social-engineering) themes centered on diplomatic events, conferences, and institutional meetings.

## Technical Analysis of TTPs

Attackers increasingly bypass traditional multi-factor authentication ([MFA](/glossary#mfa)) mechanisms by tricking users into completing legitimate authentication workflows on attacker-controlled infrastructure. This includes app password manipulation, OAuth token theft, and device code phishing.

### UNC6293 App Password and OAuth Phishing

Assessed with moderate confidence as a sub-cluster of ICE RELIC (APT29), **UNC6293** has run aggressive app password campaigns since mid-2025. App passwords grant secondary apps or devices permission to access an account without triggering standard [2FA](/glossary#two-factor-authentication-2fa) checks. 

* **Lure Mechanics:** Attackers impersonated the U.S. State Department via PDF documents containing screenshots that instructed targets to create specific app passwords, such as `ms.state.gov`.
* **Evolution:** In later campaigns, instead of asking victims to email the app password back, operators directed them to enter the generated credentials into authentication forms hosted on attacker-controlled, legitimate-looking websites.
* **OAuth Abuse:** By June 2026, GTIG observed UNC6293 incorporating OAuth phishing by requesting targets to share [authorization](/glossary#authorization) codes or full callback URLs after executing a genuine login with an external provider.

### UNC7005 Device Code and Hospitality Redirects

**UNC7005** shares targeting overlaps with UNC6293 but demonstrates lower operational security and incorporates [malware](/glossary#malware) deployment. Identified in early 2026, this cluster leverages unique tactics:

* **Targeted App Passwords:** Unlike generic templates, UNC7005 constructs target-specific app passwords mapped directly to social engineering pretexts, such as secure file sharing workflows.
* **Device Code Phishing:** The cluster targets Microsoft and WhatsApp accounts by sending emails disguised as diplomatic event invitations. Victims visiting attacker-controlled sites [spoofing](/glossary#spoofing) organizations like the GLOBSEC forum are prompted to input device codes, granting adversaries persistent access.
* **Captive Portal Abuse:** UNC7005 is also tied to hospitality captive portal redirect vectors previously highlighted by Microsoft and ReliaQuest.

## Defensive Recommendations

Defenders and high-risk personnel must adopt specific countermeasures to disrupt authentication abuse campaigns:

* **Audit App Passwords:** Regularly review enterprise and personal tenant environments for unmonitored or legacy app password creations, restricting their generation where possible.
* **Monitor OAuth Grants:** Implement strict visibility over third-party application permissions and OAuth consent grants to detect unauthorized token issuance.
* **User Awareness Training:** Train high-risk individuals—such as diplomats, researchers, and government personnel—to recognize device code phishing prompts and abnormal authentication requests disguised as conference invitations.

**Related:** [Zero-Click AI Browser Hacking Threatens Claude and ChatGPT Atlas](/blog/zero-click-ai-browser-hacking-threatens-claude-and-chatgpt-atlas), [Hotel Wi-Fi Campaigns Use CornFlake and ChocoShell Malware](/blog/hotel-wi-fi-campaigns-use-cornflake-and-chocoshell-malware)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/russian-threat-clusters-target-academia-and-government-via-auth-abuse
