Russian snoops add OAuth abuse to targeted phishing campaigns
Don't click on that State Department meeting invite
Google is tracking three distinct suspected Russian cyber-spy groups that are targeting individuals in academia, aerospace, defense, government agencies, and think tanks across Europe and the US.
The UNC (unclassified) groups, as Google calls them, have been orchestrating these highly targeted campaigns since at least last year, and they remain ongoing. Some of the phishing and OAuth-abuse operations used in the attack took place this month.
Each campaign had fewer than 100 targets, and under 10 victims, the threat-intel team told The Register.
Despite the small numbers, if you work in government, NGOs, academia, or aerospace, you may be a target, and over the past few months the Russian snoops have adapted their attacks to abuse legitimate authentication flows. This makes these types of social engineering tactics appear more legitimate – and allows the cyber operatives to compromise personal accounts across multiple platforms, Google warns.
It also means that potential victims may not recognize these as phishing attempts.
Google says it wants to raise awareness about these campaigns “so that targets can more readily recognize malicious outreach.”
In other words: don’t blindly trust that calendar invite that purports to come from the US State Department.
UNC6293
The security analysts have been tracking one of the three, UNC6293, for almost two years. UNC6293 is a suspected APT29 (aka Cozy Bear, which Google now tracks as Ice Relic – insert eyeroll) phishing squad that poses as US State Department employees to lure victims into giving the snoops long-term access to their email correspondence.
APT29 is probably best known for the 2020 SolarWinds hack, and infosec analysts from the UK and US governments, and the private sector, often link it to Russia's Foreign Intelligence Service (SVR).
On Thursday, Google’s Threat Intelligence Group (GTIG) said it's now tracking two other suspected Russian groups, UNC7005 and UNC5976, which also conduct phishing, abuse OAuth flows, and/or deploy malware to these same types of targeted individuals.
Last summer, GTIG documented UNC6293 phishing for app passwords belonging to people who are critical of Russia. In this campaign, they impersonated State Department personnel, and they’ve continued using that lure while also adding OAuth phishing into their toolkit.
“In June 2026, GTIG observed OAuth phishing where UNC6293 requested targets share either the full URL or ‘verification code’ after performing a legitimate login to an external provider,” Google threat analysts Gabby Roncone and Wesley Shields said in the Thursday report. “By providing the requested verification code the target would grant UNC6293 access to the account.”
UNC7005
GTIG also asserts, with “moderate confidence,” that UNC7005 is another initial access group connected to APT2/Cozy Bear/Ice Relic – and the SVR. This crew, first identified in February, usually targets academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the US. While it shares similarities with UNC6293, Google tracks it separately “due to its lower sophistication and poor operational security, infrastructure with divergent characteristics, and incorporation of malware.”
Reliaquest and Microsoft first sounded the alarm on this group - Redmond tracks UNC6293 as Storm-2945 - after spotting a campaign compromising captive portal networks to deliver infostealers, keyloggers, and other malware.
The Russian intelligence operatives targeted users of public Wi-Fi networks at places like hotels, conference centers, and other shared venues in the hospitality sector in an AI-assisted operation that began in February.
UNC7005 also enjoys device-code phishing for both Microsoft and WhatsApp accounts. Most recently, the phishing lures look like invitations to diplomatic events and conferences delivered via email with links to attacker-controlled websites. The crew also tends to reuse website templates.
They did this in May, we’re told, re-using the website template from an operation that used the theme of an "embassy invite." The later campaign spoofed the real GLOBSEC forum - a geopolitical gabfest that focuses on Eastern Europe.
Once victims visit the attacker-controlled website, the snoops fingerprint the victim’s system and prompt them to confirm their attendance at a conference.
“The registration process is thorough, and notably contains an epicurean wine selection, which was a theme in multiple previous ICE RELIC-linked phishing campaigns,” the Googlers wrote.
In May and June, UNC7005 carried out social engineering attacks spoofing WhatsApp and prompting the victim to either join a voice call, encrypted chat, or download a file. Joining the voice call triggers a malicious JavaScript that records audio and video of the target, which the malware uploads to the attacker’s command-and-control server.
While Google doesn’t say how the Russians use the stolen images and audio, attackers can use both to help carry out convincing social engineering campaigns.
Also in May, the goons conducted “a much broader phishing wave than any we had previously observed,” Roncone and Shields wrote. This one targeted prominent, mostly US-based academics, diplomats, and researchers whose work focused on Russia and former Soviet states.
The miscreants’ website was more “elaborately built to social engineer the target,” with specific information about a resolution supporting Ukraine, plus contact details for general questions or tech support. Those contacts were a hotline to the attackers, not a helpdesk.
information (that led to the attacker) for questions or tech issues.
When users click the button that, they believe, will download a “Summit Companion App” to read the full resolution, they inadvertently put infostealers on their own Mac OS and Windows devices.
Since August, the same crew also started both Google and Microsoft account OAuth phishing operations using cloud infrastructure.
UNC5976
Finally, UNC5976 is yet another suspected Russian cyberespionage group and again likes to steal OAuth tokens. GTIG began tracking OAuth-related activity from this crew in March 2026.
In these campaigns, UNC5976 buys up several domains with names related to file sharing and then creates a cloud project related to the domain. The domains host a fake file sharing page that prompts users to “Continue with Google” via a popup link. The links takes them to a legitimate Google OAuth login page, asks them to sign in, and after authenticating the credentials redirects the victim to a Google Cloud project URL that saves the authentication token for the attacker.
GTIG calls UNC5976 “distinct” from the other two initial access groups, and notes that this may indicate “differing strategic mandates and potential alignment with alternative Russian intelligence services.”
It also uses dedicated infrastructure for post-compromise activity instead of residential proxies, plus more malware and tooling in its OAuth operations. ®
Originally published on The Register
