cloud-security

Russian-Linked Cyber Espionage Clusters Abuse Legitimate Authentication Flows

Google Threat Intelligence Group tracks three suspected Russian-linked clusters targeting high-risk individuals through app-password phishing, OAuth abuse, device linking and malware.

Xcademia Team

Xcademia Research Team

Aug 22, 202614 min read17 views
Share:
Russian-Linked Cyber Espionage Clusters Abuse Legitimate Authentication Flows

Russian-Linked Cyber Espionage Clusters Abuse Legitimate Authentication Flows

Google Threat Intelligence Group (GTIG) has identified three distinct suspected Russian cyber espionage clusters targeting individuals across academia, aerospace and defense, government, diplomacy, nonprofits and think tanks.

The clusters, tracked as UNC6293, UNC7005 and UNC5976, use different infrastructure, tooling and operational techniques. However, they share a broader objective: gaining access to accounts and information by abusing legitimate authentication workflows.

Rather than relying only on conventional phishing pages that imitate login screens, the campaigns manipulate authentication features that users may recognize as legitimate. These include application-specific passwords, OAuth authentication, Microsoft and WhatsApp device linking, cloud-hosted authentication flows and malware delivery.

GTIG assesses with high confidence that the three clusters have a Russian nexus based on targeting patterns, phishing themes and shared operational techniques. GTIG assesses with moderate confidence that UNC6293 and UNC7005 are connected to an initial-access subcluster of ICE RELIC, formerly known as APT29.

The research highlights a broader security challenge: authentication features designed to simplify account access can also become tools in sophisticated social engineering operations.

Three Clusters, Different Methods, Similar Objective

GTIG tracks UNC6293, UNC7005 and UNC5976 separately because their infrastructure, operational security and tooling differ.

UNC6293 has focused heavily on targeted app-password and OAuth phishing.

UNC7005 has used app-password phishing, Microsoft and WhatsApp device-code or device-linking attacks, browser stealers, malware-as-a-service and OAuth phishing.

UNC5976 has concentrated on OAuth phishing, cloud infrastructure and malware, including a malicious Excel plugin tracked as HEADRUSH.

Despite these differences, account compromise remains a common theme.

info-1

UNC6293 Evolves Its App-Password Phishing

GTIG assesses with moderate confidence that UNC6293 is a subcluster of ICE RELIC responsible for initial-access operations.

The group was initially reported in 2025 conducting app-password phishing against prominent individuals who were critical of Russia.

App passwords are passcodes that can provide access to accounts for less-secure applications or devices. In the campaigns documented by GTIG, attackers attempted to persuade victims to create specific app passwords and then provide those credentials to the attacker.

Earlier operations impersonated U.S. State Department officials and instructed victims to create an app password named ms.state.gov. The instructions were delivered through PDF documents containing screenshots of the required account settings.

GTIG later observed the same screenshots being reused in October 2025.

The approach subsequently changed.

Instead of asking victims to send the app password by email, newer operations directed them to enter the password into an authentication form hosted on a legitimate-looking website.

UNC6293 also expanded into OAuth phishing.

In June 2026, GTIG observed the group asking targets to provide either a full URL or a verification code after completing a legitimate authentication process with an external provider. Providing the requested information could grant the attacker access to the account.

GTIG notes that UNC6293 campaigns are generally small in scope, often targeting fewer than five users at a time.

The lures frequently use diplomatic themes, conferences and meetings.

UNC7005 Expands the Attack Surface

UNC7005, also known as STORM-2945, was identified in February 2026.

GTIG tracks UNC7005 separately from UNC6293 despite similarities in targeting because of differences in sophistication, operational security, infrastructure and malware use.

The cluster primarily targets academic, diplomatic and nonprofit personnel across Ukraine, Western Europe and the United States.

App-Password Phishing

UNC7005 has conducted highly selective app-password phishing operations since at least February 2026.

The group uses social engineering themes tailored to individual targets. Unlike UNC6293 activity, the app-password names observed by GTIG were generally unique to individual targets.

The names could reference the activity supposedly being performed by the victim or the organization being impersonated.

This shows how the phishing content is adapted to individual targets rather than relying on a single generic lure.

Microsoft Device-Code Phishing

UNC7005 also conducts device-code phishing targeting Microsoft accounts.

The campaigns commonly use invitations for calls involving recognizable organizations connected to a target's professional field. More recent operations have used diplomatic events and conferences as themes.

Attackers send emails containing links to websites controlled by the group. These sites can imitate legitimate events and organizations.

One campaign spoofed the GLOBSEC forum.

After arriving on the page, the victim was taken through what appeared to be a conference registration process.

The site requested information, presented an identity-verification stage and ultimately displayed a device code.

GTIG also observed artifacts left over from previous campaigns. In one example, text referring to an "Embassy security policy" remained on a page otherwise designed to imitate GLOBSEC.

The group subsequently modified the operation after GTIG identified the activity.

Changes included modifying the social-engineering template, changing questions and altering the site's visual appearance.

Phishing Pages Attempted to Evade Automated Analysis

UNC7005 incorporated scripts designed to identify automated analysis environments.

One script examined browser and device characteristics, including indicators associated with browser automation and headless environments.

The checks included browser automation flags, language availability, Chrome-related browser properties and notification-permission behavior.

GTIG assessed these mechanisms as attempts to detect and evade automated analysis.

Another fingerprinting script collected characteristics including:

  • Screen width and height

  • Time zone

  • Browser language

  • Operating-system platform

  • CPU core count

  • Device memory

  • Touch capability

The information was sent to the phishing infrastructure.

This behavior illustrates that the phishing page was not necessarily static. The infrastructure could collect information about the environment visiting it and potentially adjust its behavior.

For defenders, this can make automated inspection more difficult and create differences between what a security scanner sees and what a real target experiences.

WhatsApp Device Linking Takes the Attack Further

In May and June 2026, UNC7005 conducted phishing operations impersonating WhatsApp.

The campaigns attempted to persuade targets to link their WhatsApp accounts to an attacker-controlled device.

The social-engineering themes included invitations to secure calls, chats and document sharing.

The attack began by requesting the target's phone number.

The infrastructure then initiated a legitimate WhatsApp device-linking request from the attacker's device and displayed the resulting QR code or linking code to the target.

The victim was instructed to complete the linking process.

Once the account was linked, the attacker could use the compromised WhatsApp account as part of the broader operation.

info-2

Fake Calls Could Enable Audio and Video Collection

The operation went beyond account access.

After successful device linking, the phishing page could present additional options, including a supposed voice call, encrypted chat or file transfer.

GTIG found that the fake voice-call functionality could trigger malicious JavaScript that requested access to the victim's microphone and camera.

The browser-based code used the MediaRecorder API to collect audio and video.

The recorded data was assembled into a WebM file and sent to an attacker-controlled endpoint associated with the victim's unique session.

GTIG identified an upload path in the activity:

/api/code/<unique user session id>/recording

The technique demonstrates how a phishing operation can potentially move beyond credential or account theft into collection of audio and visual information.

The research does not establish that every victim was successfully recorded.

Fake Encrypted Chats and File Transfers

The WhatsApp phishing pages could also present a fake encrypted-chat option.

The page generated chat credentials and displayed another login URL. Targets were instructed to copy the displayed username and password into the secondary page.

A separate file-transfer lure could display a download button after the WhatsApp account was linked.

GTIG was unable to determine what file may have been staged for download.

Additional details were not disclosed in the research.

UNC7005 Adds Infostealers and Malware-as-a-Service

In late May 2026, UNC7005 conducted a broader phishing campaign targeting prominent academics, diplomats and researchers, particularly those working on Russia and former Soviet states.

The phishing emails directed targets to websites designed around a summit concerning a resolution supporting Ukraine.

The site was designed to look legitimate and included information about the resolution and contact information for supposed technical support.

Targets were encouraged to download a "Summit Companion App."

Instead, the download delivered infostealer malware.

Windows Targets

Windows users were served a sample of VIDAR.

GTIG identified the sample as:

1d9299799a7b8da67c44ebec064d64542c27645f8e84de4a22ca3f6cbc843e3c

The sample was an obfuscated Go binary with the C2 address:

107.189.18[.]7

GTIG describes VIDAR as a Malware-as-a-Service infostealer that primarily targets sensitive information stored in browsers, including credentials, payment information, cookies and saved addresses.

macOS Targets

macOS users were served ATOMIC, also known as AtomicStealer.

The identified sample had the SHA256:

c5826032207d623a7f6caec8465af7364eccc355f9a48897da2a54f3e4420265

ATOMIC is also described by GTIG as a Malware-as-a-Service infostealer targeting sensitive browser information.

OAuth Phishing Moves Into Cloud Infrastructure

UNC7005 also expanded its operations into Google account OAuth phishing.

Beginning July 31, 2026, the group registered domains impersonating the Finnish Operations Center, an organization supporting Finnish companies in the defense and security markets.

Between August 6 and August 13, GTIG observed targeted phishing emails sent to individuals in or connected to the European defense industry.

The phishing pages presented options such as "Get Access" or "Sign in With Google."

The target was then redirected to a legitimate Google OAuth login page.

After authentication, the target was redirected to an attacker-controlled testing-mode and unverified cloud project.

GTIG assessed that the infrastructure was likely being used to obtain authentication tokens that could provide access to the target account.

The technique is notable because the authentication page itself can be legitimate.

The malicious activity occurs around the OAuth workflow and attacker-controlled infrastructure surrounding the authentication process.

UNC7005 Also Abused Microsoft OAuth

In early August 2026, GTIG identified another highly targeted operation in which UNC7005 sent legitimate Microsoft OAuth URLs directly to targets.

The attacker email used in this campaign was also associated with the group's Google cloud-project OAuth phishing activity.

This demonstrates the broader strategy identified by GTIG: attackers do not necessarily need to create a fake copy of every authentication page when they can manipulate the surrounding authentication workflow.

Hospitality Captive Portals Become Part of the Campaign

GTIG also linked UNC7005 to activity involving hotel and conference-center captive portals.

Beginning in April 2026, GTIG tracked infrastructure that mimicked Microsoft authentication resources.

In July, researchers observed users being redirected to this infrastructure from captive portals associated with hotels and conference centers.

The infrastructure was designed to imitate Microsoft authentication resources and was later connected to activity involving malware and device-code phishing.

GTIG linked the infrastructure used in the hospitality campaign to other UNC7005 operations dating back to April 2026.

Several infrastructure overlaps supported the assessment.

Three Microsoft Outlook Web Access-themed domains registered between July 16 and July 23 were later linked to the hospitality campaign:

  • owa-ms365[.]com

  • m365-owa[.]com

  • ms365-device[.]com

GTIG also identified relationships between these domains, earlier Microsoft-themed infrastructure and domains used in previous device-code phishing operations.

ENGINELIGHT and CHERRYPIE Add Another Malware Layer

UNC7005 also used malware known as ENGINELIGHT.

A domain spoofing Microsoft was used as its C2 infrastructure in a limited phishing campaign in early May 2026.

GTIG additionally observed CHERRYPIE, also known as ChocoShell, a PowerShell infostealer.

Researchers found multiple artifacts suggesting that samples of CHERRYPIE may have been generated using a large language model.

GTIG also observed functional overlaps between malware families used by UNC7005 and noted the group's use of Malware-as-a-Service.

Based on these observations, GTIG suspects CHERRYPIE may be based on an infostealer purchased from MaaS operators.

This remains an assessment rather than confirmed attribution.

UNC5976 Takes a Different Approach

UNC5976 is tracked separately from UNC6293 and UNC7005.

GTIG began tracking its OAuth-related activity in March 2026 and assesses that it is a suspected Russian cyber espionage cluster with an authentication focus.

Its operations have primarily targeted military, aerospace, defense-industrial and nonprofit or think-tank organizations.

Much of the geographic targeting has focused on Ukraine and Armenia.

UNC5976 has used file-sharing themes for OAuth phishing.

Attackers purchased domains resembling file-sharing services and created cloud projects associated with those domains.

A fake file-sharing page would eventually display a login dialog.

When the victim selected "Continue with Google," they were sent to a legitimate Google OAuth login page.

After authentication, the victim was redirected to an attacker-controlled Google Cloud project.

GTIG found that malicious scripts in the cloud project retrieved the authentication token from the URL and stored it for later retrieval by the operator.

UNC5976 Rebuilds After Disruption

GTIG said that within approximately three months of its initial discovery and disruption of UNC5976 infrastructure, the group created at least 12 new domains and related infrastructure.

Google took steps to disable the cloud projects associated with the activity and disrupt the phishing operations.

GTIG now assesses that UNC5976 is migrating some of its phishing infrastructure away from Google infrastructure to other providers.

HEADRUSH Malware Targets Excel Users

UNC5976 has also used a malicious Excel plugin tracked by GTIG as HEADRUSH.

In April 2026, researchers observed a HEADRUSH sample that ultimately led to an HTML Application downloader.

The sample was distributed through a domain impersonating a Ukrainian research institute and may have targeted a Ukrainian aerospace and imaging company.

GTIG said it could not determine the full extent of the infection chain.

The identified HEADRUSH SHA256 is:

2c7f4165967d6f7737b3fef87959846920b57a5368b531ad1427c7214d4c41a2

What Connects the Three Clusters?

GTIG assesses with high confidence that UNC6293, UNC7005 and UNC5976 have a Russian nexus.

However, the groups should not be treated as a single operational entity.

UNC6293 and UNC7005 share significant similarities and are assessed with moderate confidence to be related to an ICE RELIC subcluster focused on initial access.

Historical and current campaigns show overlap in:

  • Academia

  • Diplomacy

  • NGOs

  • Defense

  • Geographic targeting

  • Diplomatic event themes

  • Wine-related themes

  • Authentication-focused social engineering

GTIG also notes that UNC6293 and UNC7005 heavily rely on commercial residential proxies for post-compromise activity.

UNC5976 remains distinct. It uses dedicated infrastructure for post-compromise activity rather than residential proxies and has a heavier malware and tooling footprint.

Why These Attacks Are Difficult to Detect

The major lesson from the research is not simply that phishing is becoming more sophisticated.

It is that attackers are increasingly abusing legitimate authentication mechanisms.

An attacker may persuade a victim to:

  • Create an app password

  • Complete a legitimate OAuth login

  • Provide an authentication code

  • Link a messaging account to another device

  • Download a seemingly legitimate application

  • Authenticate through a cloud-hosted workflow

From the user's perspective, individual steps may look normal.

That creates a visibility challenge for defenders.

The targeted accounts are often personal rather than corporate domain-joined accounts, which can make monitoring and remediation more difficult for organizations.

GTIG also highlights the use of encrypted messaging applications for initial outreach. This can reduce visibility into the earliest stages of an operation.

Once an account is compromised, attackers may also use the legitimate account to target additional individuals.

info-3

Security Recommendations

GTIG recommends several measures for users and organizations.

Verify Unexpected Invitations

Do not proceed past warnings for suspicious websites.

Before entering credentials or authenticating, inspect the URL carefully.

For invitations from unknown contacts, verify the event directly with the organization using contact information obtained independently of the invitation.

Treat Familiar-Looking Identities Carefully

An email or message can appear to come from a legitimate person or organization while the underlying persona has been spoofed.

Users should therefore validate unexpected requests through another communication channel.

Avoid Unnecessary App Passwords

Google says app passwords are not recommended or necessary in most cases.

They should not be treated as account or identity-verification tools.

Users should never share an app password with another person.

Legacy app passwords associated with lost, stolen or unused devices should be revoked.

Strengthen Protection for High-Risk Accounts

Google recommends that high-risk users consider the Advanced Protection Program.

Enterprise customers can also restrict account configurations to strengthen authentication requirements.

Audit Linked Messaging Devices

Organizations and high-risk individuals using messaging applications should regularly review linked devices.

Additional measures recommended by GTIG include:

  • Enforcing registration locks and two-factor authentication where available

  • Regularly auditing linked devices

  • Using safety numbers or security codes to validate contacts through an independent communication channel

Technical Analysis: What the Browser Code Reveals

The research includes code examples illustrating technical mechanisms used in the campaigns.

One fingerprinting script collected browser and device characteristics and sent them to attacker infrastructure.

Another script checked for signs of browser automation and headless environments.

The WhatsApp campaign contained a more invasive browser capability.

After a victim entered the fake voice call, JavaScript could request microphone and camera permissions, create a browser-based recording session and upload the resulting media to the attacker's server.

The implementation used the browser's getUserMedia() and MediaRecorder capabilities.

This is important because the behavior did not require a traditional executable to perform the recording. The browser itself provided the functionality after the victim granted the relevant permissions.

The exact JavaScript implementation is not reproduced here because the security significance lies in the behavior and attack flow rather than reproducing the complete implementation.

Selected Indicators of Compromise

The following indicators are reproduced from the Google Threat Intelligence Group research.

Network Indicators

Indicator

Attribution

Notes

dosportal.app

UNC6293

Phishing domain

foreignrelations.us

UNC6293

Phishing domain

107.189.18.7

-

C2 for VIDAR

fewfwfwfwfwf.info

-

C2 for AtomicStealer first payload

196.251.107.171

-

C2 for AtomicStealer second payload

miov2iaiaoubqosiqoiajwowiwjso.online

-

C2 for AtomicStealer second stage

mioisiskwowiwjowuwjwolab.club

-

C2 for AtomicStealer second stage

chamber-ua.org

UNC7005

Phishing domain

wa-connect.eu

UNC7005

Phishing domain

wa-connect.net

UNC7005

Phishing domain

wa-invite.com

UNC7005

Phishing domain

wa-device.com

UNC7005

Phishing domain

wa-meeting.com

UNC7005

Phishing domain

shopinvite.org

UNC7005

Phishing domain

my-invite.org

UNC7005

Phishing domain

globsec.net

UNC7005

Phishing domain

statistic-ms.live

UNC7005

ENGINELIGHT C2

owa-ms365.com

UNC7005

Attacker domain

m365-owa.com

UNC7005

Attacker domain

ms365-device.com

UNC7005

Attacker domain

ms365-live.com

UNC7005

Attacker domain

31.57.243.154

UNC7005

Related IP

38.146.28.75

UNC7005

Related IP

104.194.159.150

UNC7005

Related IP

finishoperations.com

UNC7005

Phishing domain

finishoperations.org

UNC7005

Phishing domain

foc-share.com

UNC7005

Phishing domain

share-foc.com

UNC7005

Phishing domain

internal-share.com

UNC7005

Phishing domain

foc-share.org

UNC7005

Phishing domain

drive.google.verify-drive.com

UNC5976

Phishing domain

mail.kiis.co.uk

UNC5976

Malware distribution domain

File Indicators

SHA256

Malware / File

Attribution

Notes

5b8d50c2e8cc3038b7c6e6dbf1219f6e814930a1e3c0053143a1191ae67f8ffc

n/a

UNC7005

GLOBSEC phishing page

a06a8fd1b6fa1924199a4540cf16d089217ce8f78c617739946f145fd1fc88c1

n/a

UNC7005

Finnish Operations Center OAuth phishing landing page

1d9299799a7b8da67c44ebec064d64542c27645f8e84de4a22ca3f6cbc843e3c

VIDAR

UNC7005

VIDAR used by UNC7005

c5826032207d623a7f6caec8465af7364eccc355f9a48897da2a54f3e4420265

ATOMIC

UNC7005

ATOMIC used by UNC7005

125752ad7c20d715920a3b2fb0fdde660f07b3f2b053665cf38c2d6d9de86e1e

ENGINELIGHT

UNC7005

-

403b624e35777cbc07dbe66398b21bba70396a20b859c880732338ce1dd1f41f

CHERRYPIE

UNC7005

-

28f622028e690c943f7fa9aca426c07cab52b5aaba757ef8a3328609c0b3bec3

CHERRYPIE

UNC7005

-

be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c

CHERRYPIE

UNC7005

-

1e3ee845fde739fcd3ca9ce62c7f142a7c501d11db4c4fb294d4939f12d0f916

CHERRYPIE

UNC7005

-

6f7090895c1c3dee30de6b3f098ca3a788dc198646e5293a8b1210430b0add97

CHERRYPIE

UNC7005

-

20e20b074967ed6f6e04d609ccec5ff7492665ef25f894c90c2ddc92fa47ac38

CHERRYPIE

UNC7005

-

ca3be5885afb3eb3bb19341e2653212200c568f3f900e0b2f04de9ba209aed25

CHERRYPIE

UNC7005

-

2c7f4165967d6f7737b3fef87959846920b57a5368b531ad1427c7214d4c41a2

HEADRUSH

UNC5976

-


Google Security Operations

Google says customers with the Enterprise Plus license have access to rules covering this activity through the Applied Threat Intelligence - Curated Prioritization rule pack.

The activity can be detected through Applied Threat Intelligence alerts, where indicators are contextualized using YARA-L rules and Google threat intelligence context.

This provides security teams with an intelligence-driven approach to prioritizing relevant alerts.

Authentication Abuse Is Becoming Harder to Recognize

The campaigns documented by GTIG highlight a broader industry shift toward abusing legitimate authentication features rather than relying only on conventional fake login pages.

The attackers described in the research use app passwords, OAuth, device linking, cloud projects, messaging applications and malware as different paths toward the broader objective of gaining access to accounts and information associated with high-value targets.

For enterprises, this could mean that authentication monitoring needs to consider more than failed passwords and suspicious login locations.

A legitimate authentication event can still be part of a malicious sequence when it has been initiated through social engineering.

The use of personal accounts and encrypted messaging platforms also creates additional visibility challenges for organizations.

GTIG's research shows why users should treat unexpected authentication requests, invitations, device-linking prompts and application downloads with caution, even when the surrounding experience appears legitimate.

#Cybersecurity#ThreatIntelligence#CyberEspionage#Phishing#OAuth#AccountTakeover#RussianCyberThreats#Malware

About the Author

X
Xcademia Team
Xcademia Research Team
Share:
Learn to stop attacks like this oneCybersecurity Engineer Bootcamp: live cohorts enrolling now, Career+ support included.