Build1 distinct publisher3 min readUpdated
Google's threat intel group ties UNC6293, UNC7005 and UNC5976 to attacks on OAuth consent, app passwords, device codes and WhatsApp linking. The login succeeds; the token leaves anyway.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Multi-factor authentication settles whether the person completing a login is the account holder. Every technique in the Google Threat Intelligence Group report lets that check succeed and takes what the platform issues afterwards. An OAuth consent grant, an application specific password, a device code approval and a linked WhatsApp device are authorization artifacts rather than authentication events. They outlive the session that created them and can be replayed without a password, which is why GTIG says a finished MFA rollout stops none of the three clusters [3].
In the UNC5976 flow the target lands on a file sharing page, waits out a short delay, clicks a Continue with Google button and arrives at the genuine Google OAuth page, correct domain, valid certificate. The redirect afterwards lands on a Google Cloud project URL, where scripts strip the authentication token out of the URL and stage it for an operator [10]. The victim authenticates, satisfies MFA, and is never asked for a credential on an attacker-owned domain [14]. Awareness training built on reading the address bar has nothing to catch [14].
The WhatsApp work is harder to defend, because nothing is intercepted at all. According to GTIG, UNC7005 pages spoofing WhatsApp in May and June 2026 asked the target for a phone number, used it to raise a real device link request against an attacker-controlled device, then displayed the QR code and linking code that WhatsApp itself returned, plus instructions for completing the link [15][16]. Every string on the screen is authentic. Once the link completes the attacker device receives message traffic, and the page pushes the target toward a voice call, an encrypted chat or a file download; choosing the call runs JavaScript that records audio and video and ships it to a command and control endpoint [16][17].
The clusters have also thought about who is watching. GTIG places the targeting on personal accounts across multiple platforms rather than corporate mailboxes [4], where no employer holds the sign-in log, and both UNC6293 and UNC7005 route post-compromise activity through commercial residential proxies so the session appears to originate in consumer IP space [7]. UNC6293 is assessed as a sub-cluster of Ice Relic, formerly APT29 [5]; UNC7005 is the group Microsoft tracks as Storm-2945 [6].
Google counted no fewer than 12 new UNC5976 domains and their supporting infrastructure created since March 2026, and disrupted all of them [11]. Measured against a report dated 20 August 2026, that is a build rate near two domains a month [19], and UNC5976's response to the disruption was to move its phishing pages onto other providers [12]. The same cluster runs malware in parallel: HEADRUSH, a rogue Excel plugin found in April 2026 that delivers an HTA downloader, distributed from a domain impersonating a Ukrainian research institute, with indications of use against a Ukrainian aerospace and imaging company whose full infection GTIG says it cannot scope [13].
That puts the durable fix on the platform side of the flow, where the grant is minted. A device link request the account holder did not start on their own handset should not be completable from a web page. Short of that, the defender's only move is revocation after the fact, and revocation depends on noticing, which is precisely what the residential proxies are there to prevent [7].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Google Threat Intelligence Group published research on August 20, 2026 linking three suspected Russian espionage clusters, UNC6293, UNC7005 and UNC5976, to phishing campaigns that never ask for a password.
UNC6293, UNC7005 and UNC5976 target academia, aerospace and defense, government and think tank personnel across Europe, Ukraine and the United States.
All three clusters attack the authentication flow itself, using OAuth consent, application specific passwords, device code grants and WhatsApp device linking; a completed MFA rollout stops none of it.
GTIG researchers Gabby Roncone and Wesley Shields describe the activity as persistent and adaptive, focused on personal accounts across multiple platforms rather than corporate mailboxes.
UNC6293 is assessed as a sub-cluster of Ice Relic, previously APT29, also tracked as Cozy Bear and Midnight Blizzard.
UNC7005, also tracked by Microsoft as Storm-2945, was identified in February 2026.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed vendor research, single secondary retelling
The technical account is specific and internally consistent: named clusters, named GTIG researchers, dated campaign windows, step-by-step flows, a counted domain total and a named malware family. But the whole cluster is one dev.to summary of Google's report, with no link to or excerpt from the primary publication, no indicators of compromise, and no independent source confirming the attribution or the disruption count.
Confirmed in-the-wild activity, narrow campaign volumes
These are techniques observed in live espionage operations, not proofs of concept: dated campaigns from February to June 2026, at least 12 purpose-built domains disrupted, a malware family found in April 2026, and an observed pivot to new providers after takedown. Adoption is bounded, however — targeting is deliberately small (campaigns hitting fewer than five users at a time) and confined to academia, defense, government and NGO personnel, with no victim counts or confirmed compromise totals disclosed.
Mechanics justified, generalization overreached
The core technical claim — that these flows produce a valid provider-issued session, so completed MFA and URL-bar training do not stop them — is supported by the described mechanics. The framing stretches beyond that: 'MFA completion changes nothing' generalizes narrowly targeted espionage against personal accounts of a specific professional population into a universal control failure, and headline superlatives ('most consequential technique') are editorial rather than evidenced. The cluster also reports the successful Google disruption while framing the response as a broad failure, and offers no countermeasures, which tilts the story toward inevitability.
Vendor research crediting its own takedown
The underlying research is authored by Google Threat Intelligence Group about abuse of Google identity and cloud infrastructure, and it foregrounds Google's own disruption of all 12 counted domains — a structural incentive to frame the platform as responsive while attributing residual risk to persistent state actors and to personal accounts outside enterprise control. Attribution naming conventions also serve vendor tracking brands (Ice Relic, Microsoft's Storm-2945, Zscaler's SPIKEDWINE). The republishing publisher has no disclosed commercial stake visible in the cluster, so the incentive read rests on the research author, not the outlet.
Coherent but single-publisher and unlinked
Confidence is capped by cluster structure: one publisher, one article, no primary document, no second outlet, and no statement from the platforms whose features are abused. Within those limits the account is dense, dated, self-consistent and carries its own scope caveats, and the technique claims are mechanically plausible, so the substance is likely broadly accurate even though little of it is independently verifiable here.
build
Google: Russia-linked crews get targets to hand over app passwords, OAuth codes and WhatsApp devices1 distinct publisher
leadership
Russia-linked crew keeps winning with app passwords and device codes1 distinct publisher
invest
Rust's arrayref hijack lasted 86 minutes, and Wiz ties it to North Korea1 distinct publisher
product
Pearson's inversion: in learning products, the correct answer can be the product failure1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 23, 2026