Published · 2d agoSecurity3 min read
Moscow's crews stopped stealing passwords. Now they ask victims to approve the login.
Google's threat intelligence team ties three suspected Russian clusters to abuse of Google OAuth, app passwords and device linking. MFA completes normally, so consent telemetry is the control.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to target individuals.
- The clusters are UNC6293, UNC7005 and UNC5976.
- Google Threat Intelligence Group researchers Gabby Roncone and Wesley Shields wrote that the clusters engage in persistent, adaptive phishing campaigns using sophisticated social engineering to compromise personal accounts across multiple platforms, in a report published the day of the article.
- UNC5976 uses OAuth phishing techniques and automates collection of tokens by abusing cloud infrastructure, and is believed active since at least March 2026.
- GTIG said UNC5976 purchased domains, usually with file-sharing-related names, created a cloud project related to each domain, and hosted a fake file sharing page that displays a pop-up login dialog after the target has been on the page for a few seconds.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Google Threat Intelligence Group has published research attributing three suspected Russian espionage clusters, UNC6293, UNC7005 and UNC5976, to persistent phishing campaigns that hijack personal accounts by routing targets through legitimate authentication flows [1][2][3]. The consequence is uncomfortable for anyone whose account-security programme ends at multi-factor authentication: the victim signs in on the real provider page, the second factor succeeds, and what gets stolen is the authorization issued afterwards [1].
The clearest mechanics belong to UNC5976, assessed active since at least March 2026 [4]. According to GTIG, the group buys domains with file-sharing-themed names, stands up a cloud project tied to each one, and hosts a fake file-sharing page that waits a few seconds before presenting a pop-up login dialog [5]. The "Continue with Google" button in that dialog sends the target to the genuine Google OAuth login page [6]. After a successful sign-in, the victim lands on a Google Cloud project URL running scripts that pull the authentication token out of the URL and stage it for later use [7]. Google says the actor built at least 12 domains and supporting infrastructure since March 2026, that all of it has been disrupted, and that the disruption pushed UNC5976 off Google infrastructure onto other hosting providers [8][9].
UNC6293, first documented by Google and the Citizen Lab in June 2025, is assessed as a sub-cluster of Ice Relic, formerly APT29, also tracked as Cozy Bear and Midnight Blizzard [10]. Its earlier work abused Google application specific passwords to take over accounts [11]. The current campaigns are deliberately small, fewer than five users at a time, with operators impersonating State Department officials and using diplomatic conference and meeting lures, some of which Volexity described in December 2025 [12]. As recently as June 2026, Google observed the group performing OAuth phishing by asking targets to hand over either the full URL or the verification code after completing a legitimate login at an external provider [13].
UNC7005, also tracked as Storm-2945 and identified in February 2026, targets academic, diplomatic and nonprofit personnel in Ukraine, Western Europe and the United States [14]. Google assesses both UNC6293 and UNC7005 as part of an Ice Relic sub-group focused on initial access, using commercial residential proxies for post-compromise activity [15]. UNC7005 runs app password phishing and device code phishing against both Microsoft and WhatsApp accounts, with the Microsoft lures arriving as invitations to diplomatic events [16][17]. Across the three clusters that is three separate legitimate mechanisms being turned into an access path: OAuth consent, application specific passwords, and device linking [2].
Not everything here is consent abuse. UNC5976 also deploys a rogue Excel plugin tracked as HEADRUSH, found in April 2026, which delivers an HTA downloader and was distributed from a domain impersonating a Ukrainian research institute, with indications of use against a Ukrainian aerospace and imaging company [18]. Google puts the group's focus on military, aerospace, the defense industrial base and NGOs and think tanks, concentrated on Ukraine and Armenia [19]. The wider target set spans academia, aerospace and defense, governments and think tanks in Europe, plus academia and think tanks in the United States [20].
What to watch: whether OAuth grant creation, app password issuance and linked-device events are actually alerted on rather than merely logged. Campaigns sized under five recipients will not trip volume thresholds [12]. And indicator lists age fast when takedowns push an actor to a new host [9].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to target individuals.
ReportedView cited source - [3]
Google Threat Intelligence Group researchers Gabby Roncone and Wesley Shields wrote that the clusters engage in persistent, adaptive phishing campaigns using sophisticated social engineering to compromise personal accounts across multiple platforms, in a report published the day of the article.
- [4]
UNC5976 uses OAuth phishing techniques and automates collection of tokens by abusing cloud infrastructure, and is believed active since at least March 2026.
ReportedView cited source - [5]
GTIG said UNC5976 purchased domains, usually with file-sharing-related names, created a cloud project related to each domain, and hosted a fake file sharing page that displays a pop-up login dialog after the target has been on the page for a few seconds.
- [6]
The pop-up features a "Continue with Google" button that, if clicked, redirects the victim to the legitimate Google OAuth login page.
ReportedView cited source
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityaffairs.comPierluigi Paganini2d agoFake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
Additional citations
- Google Threat Intelligence Group (GTIG)
- GTIG



