Security1 distinct publisher3 min readUpdated
Google's threat intelligence team ties three suspected Russian clusters to abuse of Google OAuth, app passwords and device linking. MFA completes normally, so consent telemetry is the control.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Google Threat Intelligence Group has published research attributing three suspected Russian espionage clusters, UNC6293, UNC7005 and UNC5976, to persistent phishing campaigns that hijack personal accounts by routing targets through legitimate authentication flows [1][2][3]. The consequence is uncomfortable for anyone whose account-security programme ends at multi-factor authentication: the victim signs in on the real provider page, the second factor succeeds, and what gets stolen is the authorization issued afterwards [1].
The clearest mechanics belong to UNC5976, assessed active since at least March 2026 [4]. According to GTIG, the group buys domains with file-sharing-themed names, stands up a cloud project tied to each one, and hosts a fake file-sharing page that waits a few seconds before presenting a pop-up login dialog [5]. The "Continue with Google" button in that dialog sends the target to the genuine Google OAuth login page [6]. After a successful sign-in, the victim lands on a Google Cloud project URL running scripts that pull the authentication token out of the URL and stage it for later use [7]. Google says the actor built at least 12 domains and supporting infrastructure since March 2026, that all of it has been disrupted, and that the disruption pushed UNC5976 off Google infrastructure onto other hosting providers [8][9].
UNC6293, first documented by Google and the Citizen Lab in June 2025, is assessed as a sub-cluster of Ice Relic, formerly APT29, also tracked as Cozy Bear and Midnight Blizzard [10]. Its earlier work abused Google application specific passwords to take over accounts [11]. The current campaigns are deliberately small, fewer than five users at a time, with operators impersonating State Department officials and using diplomatic conference and meeting lures, some of which Volexity described in December 2025 [12]. As recently as June 2026, Google observed the group performing OAuth phishing by asking targets to hand over either the full URL or the verification code after completing a legitimate login at an external provider [13].
UNC7005, also tracked as Storm-2945 and identified in February 2026, targets academic, diplomatic and nonprofit personnel in Ukraine, Western Europe and the United States [14]. Google assesses both UNC6293 and UNC7005 as part of an Ice Relic sub-group focused on initial access, using commercial residential proxies for post-compromise activity [15]. UNC7005 runs app password phishing and device code phishing against both Microsoft and WhatsApp accounts, with the Microsoft lures arriving as invitations to diplomatic events [16][17]. Across the three clusters that is three separate legitimate mechanisms being turned into an access path: OAuth consent, application specific passwords, and device linking [2].
Not everything here is consent abuse. UNC5976 also deploys a rogue Excel plugin tracked as HEADRUSH, found in April 2026, which delivers an HTA downloader and was distributed from a domain impersonating a Ukrainian research institute, with indications of use against a Ukrainian aerospace and imaging company [18]. Google puts the group's focus on military, aerospace, the defense industrial base and NGOs and think tanks, concentrated on Ukraine and Armenia [19]. The wider target set spans academia, aerospace and defense, governments and think tanks in Europe, plus academia and think tanks in the United States [20].
What to watch: whether OAuth grant creation, app password issuance and linked-device events are actually alerted on rather than merely logged. Campaigns sized under five recipients will not trip volume thresholds [12]. And indicator lists age fast when takedowns push an actor to a new host [9].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to target individuals.
Google Threat Intelligence Group researchers Gabby Roncone and Wesley Shields wrote that the clusters engage in persistent, adaptive phishing campaigns using sophisticated social engineering to compromise personal accounts across multiple platforms, in a report published the day of the article.
UNC5976 uses OAuth phishing techniques and automates collection of tokens by abusing cloud infrastructure, and is believed active since at least March 2026.
GTIG said UNC5976 purchased domains, usually with file-sharing-related names, created a cloud project related to each domain, and hosted a fake file sharing page that displays a pop-up login dialog after the target has been on the page for a few seconds.
The pop-up features a "Continue with Google" button that, if clicked, redirects the victim to the legitimate Google OAuth login page.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-vendor, single-outlet
The underlying material is unusually specific for threat reporting: named GTIG authors, three named clusters with aliases, dated first observations, a step-by-step OAuth token-staging chain, a named malware artifact and an infrastructure count. That specificity raises evidence quality. It is capped, however, by provenance: one publisher relaying one vendor report, with no independent confirmation, no primary telemetry shown and no comment from the other platforms whose flows are abused.
Operationally live across three actors, scope unquantified
Read as operational uptake of the technique rather than product adoption: three separate clusters are using legitimate-auth abuse concurrently, across Google OAuth, app specific passwords, Microsoft device code and WhatsApp device linking, with dated campaigns through June 2026 and at least 12 pieces of disrupted infrastructure. Uptake is therefore established as real and recurring. It stays mid-range because victim counts are absent or tiny by design (fewer than five users per UNC6293 wave), the HEADRUSH infection scope is explicitly unknown, and all activity data comes from one telemetry vantage point.
Mildly overstated framing over solid mechanics
The technical body is measured and hedged, but the packaging runs ahead of it: the framing that Moscow's crews 'stopped stealing passwords' overstates a picture in which app specific password phishing is still central to two of the three clusters, and the claim that consent telemetry 'is the control' is an editorial inference rather than a reported finding. Attribution language in the source is appropriately conditional ('suspected', 'believed', 'assessed'), which limits the gap.
Vendor-authored disclosure about its own surfaces
Google is simultaneously the operator of the abused OAuth and Cloud surfaces, the sole source of attribution and telemetry, and the party crediting itself with disrupting all 12 domains and forcing the actor onto rival providers. That combination is a real incentive to frame platform abuse as detected, contained and outbound-migrating. The publisher's incentive is volume-driven same-day relay of a vendor report rather than independent verification, and no counterparty (Microsoft, WhatsApp, Citizen Lab, Volexity) is given room to qualify the account.
Moderate: credible mechanics, thin corroboration
Confidence is moderate. The mechanics, dates and actor relationships are internally consistent and specific enough to act on defensively, and prior-art anchors (Citizen Lab June 2025, Volexity December 2025, Zscaler's SPIKEDWINE) lend continuity. But the entire cluster is one article relaying one vendor, several key numbers are the vendor's own estimates, victim impact is unquantified, and the story's sharpest conclusions about MFA and consent telemetry are derived rather than reported.
build
Grok 4.6 lands in Copilot two days after launch, and the model picker becomes a procurement problem1 distinct publisher
product
Washington's secret AI test is coming for open weights, and release dates go with it2 distinct publishers
invest
Your 2027 compute plan was priced before the states started taxing electrons1 distinct publisher
security
Mandiant found 100 high-severity bugs in two days. Plan for the other side doing the same.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026