Tre cluster legati alla Russia usano OAuth, WhatsApp e malware contro obiettivi occidentali
APT

Illustrative image generated with AI

Three Russia-Linked Clusters Use OAuth, WhatsApp, and Malware Against Western Targets

Explore three Russia-linked cyber-espionage clusters using OAuth, WhatsApp, and malware against Western researchers, officials, and analysts in phishing campaigns.

Text generated by artificial intelligence, published without human review. AI transparency

Phishing Without Obviously Fake Login Pages

Google Threat Intelligence Group has described three suspected Russia-linked cyber-espionage clusters: UNC6293, UNC7005, and UNC5976. The campaigns target researchers, academics, government officials, think tank analysts, and defense-sector personnel in Europe and the United States.

The report was published on August 21, 2026. The operations share a common feature: abuse of legitimate authentication and sharing workflows rather than reliance on obviously counterfeit login pages.

The attackers exploit app passwords, OAuth authorizations, device codes, WhatsApp accounts, and cloud authentication screens. To the victim, the process may appear legitimate: the domain looks plausible, authentication takes place through a familiar service, and the request is embedded in a carefully constructed conversation.

The activity also creates visibility challenges for organizations. Initial contact may occur through a personal account that is not associated with the corporate domain and therefore falls outside standard email controls. The potential use of encrypted messaging makes it even harder to intercept the attempt before compromise.

UNC6293 Relies on App Passwords and OAuth Tokens

UNC6293 is the longest-documented and most precisely attributed cluster. Google assesses with moderate confidence that it is a subgroup of ICE RELIC, also known as APT29, which is active in initial-access operations.

The group typically targets fewer than five victims at a time. Lures are often built around upcoming diplomatic events or conferences. Since its first documented activity in June 2025, UNC6293 has impersonated U.S. State Department officials.

Victims were asked to configure a specific app password. The value was chosen by the attackers and communicated directly to the target. Once configured, the password enabled account access without triggering two-factor authentication.

The technique is particularly deceptive because it does not necessarily require theft of the victim’s primary password. Instead, the attacker abuses a legitimate account feature, turning it into an alternative access path that is harder to detect.

In October 2025, the group reused screens from the June lures, including the reference to ms.state.gov, changing only the surrounding text. In June 2026, UNC6293 added OAuth-based campaigns.

In these cases, after accessing a legitimate service, the victim was asked to share a URL or a “verification code.” The goal was to obtain valid tokens. Authentication appeared to complete normally, but the next step gave the attackers the authorization needed to operate within the account.

UNC7005 Combines Device Codes, WhatsApp, and Infostealers

UNC7005, identified by Microsoft as STORM-2945, was first observed in February 2026. This cluster is also considered linked to ICE RELIC, although Google describes it as less sophisticated and less operationally disciplined than UNC6293.

Its activity is broader, encompassing phishing involving app passwords, device codes for Microsoft accounts and WhatsApp, OAuth campaigns, malware, and fake invitations to conferences or calls with organizations relevant to the victim.

One representative case involved the GLOBSEC forum scheduled for May 2026. UNC7005 created a page that imitated an event invitation and collected detailed registration information, including a wine selection for a fictitious dinner.

At the end of the process, the site displayed a Microsoft device code to be entered by the user. The form still contained a reference to the “Embassy security policy,” left over from an earlier lure template. After the page was reported, the group changed the template within days, attributing the change to alleged “technical difficulties.”

Operations targeting WhatsApp followed a similar pattern. Victims were invited to join a call, open an encrypted chat, or download a document. The page then asked them to link their account to a device controlled by the attackers.

In some cases, malicious JavaScript also requested access to the microphone and camera. If the user granted permission, the browser recorded images and audio and sent them to the attackers.

Between late May 2026 and June 2026, UNC7005 conducted social-engineering operations targeting diplomats, U.S. academics, and researchers focused on Russia. A broader campaign offered a fake application called Summit Companion App, presented as a tool for reading a document supporting Ukraine.

The file delivered VIDAR to Windows users and ATOMIC, also known as Atomic Stealer, to macOS users. Both are commercial infostealers sold as-a-service. VIDAR can steal saved browser credentials, cookies, and payment data; ATOMIC is designed to collect similar information from Apple systems.

Neither tool was developed specifically for this operation. The email address used in the campaign was also nearly identical to one UNC6293 had used the previous year.

Hotel Infrastructure and Possible LLM-Generated Code

Google also directly links UNC7005 to the campaign targeting captive portals at hotels and conference centers, activity previously reported by Reliaquest and Microsoft and attributed to Midnight Blizzard.

The infrastructure was traced to April 2026, when domains imitating Microsoft authentication resources began appearing. Google Safe Browsing progressively added the domains to its blocklists. By mid-July 2026, they were receiving redirects from captive portals at hotels and conference venues.

IP-address analysis links this infrastructure to the GLOBSEC device-code operation and to ENGINELIGHT, a Go-based malware family used in a separate, limited UNC7005 operation conducted in May 2026.

The cluster also used CHERRYPIE, also known as ChocoShell, a PowerShell infostealer. The analyzed files contain comments and references apparently consistent with AI-generated code. Google therefore considers it possible that an LLM was used in the malware’s development.

CHERRYPIE collects data that partially overlaps with information stolen by commercial infostealers. It may therefore be a customized variant of a malware-as-a-service tool. This hypothesis does not, however, confirm the origin of the code.

UNC5976 Targets Defense Organizations and Groups Linked to Ukraine and Armenia

UNC5976 is the most distinct of the three clusters. It focuses on military, aerospace, defense industrial base, and NGO organizations, with particular attention to Ukraine and Armenia.

Its OAuth operations are more automated. The group registers file-sharing-related domains, creates Google Cloud projects associated with those domains, and uses scripts hosted in the cloud. The victim sees an apparently genuine Google authentication screen inside a fake file-sharing page; signing in allows the attackers to collect authentication tokens.

After Google disrupted the infrastructure, UNC5976 had created at least 12 new domains within three months and was migrating to hosting providers outside the Google ecosystem. This demonstrates the group’s ability to rapidly rebuild its operations.

In April 2026, the cluster distributed HEADRUSH, a malicious Excel add-in, through a domain imitating a Ukrainian research institute. The potential target was a Ukrainian company active in the aerospace and imaging sectors.

HEADRUSH ultimately leads to an HTA downloader, but the full infection chain has not been reconstructed.

How to Reduce the Risk of Compromise

Users should never create app passwords at the request of a third party. They should also revoke any existing app passwords they do not recognize and regularly review the devices linked to WhatsApp.

An OAuth request received through an unsolicited message should be treated as suspicious, even when the page looks professional or uses a familiar service. The same applies to conference invitations, calls, and document-sharing requests that require device codes or the linking of new devices.

Microphone and camera access should not be granted to unverified pages. Applications distributed through events, institutions, or known organizations should be downloaded only from official channels.

For high-risk individuals, the Google Advanced Protection Program completely prevents the creation of app passwords. Where permitted by organizational policy, organizations should monitor personal accounts used for sensitive activities, OAuth grants, linked WhatsApp devices, and domains impersonating Microsoft, Google, diplomatic institutions, conferences, or research centers.

It is not known whether these activities are associated with specific software vulnerabilities or with entries in CISA’s KEV Catalog. The primary risk comes from the abuse of legitimate mechanisms, resulting in compromises that can evade traditional enterprise security controls.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsRussia-linkedcyber-espionageOAuth abuseWhatsApp phishingmalwareUNC6293UNC7005Western targets
Back to home