Three suspected Russian cyber espionage clusters are increasingly abusing legitimate authentication mechanisms to compromise individuals working in academia, aerospace and defense, government, diplomacy, and think tanks across Europe and the United States.
The clusters, tracked by Google Threat Intelligence Group (GTIG) as UNC6293, UNC7005, and UNC5976, have adopted phishing techniques that rely less on conventional fake login pages and more on legitimate authentication workflows. This makes the attacks harder for victims to recognize and potentially more difficult for defenders to distinguish from normal account activity.
Google said the campaigns are persistent and highly targeted, with attackers using sophisticated social engineering to compromise personal accounts across multiple platforms. The operations demonstrate a recurring Russian-linked focus on abusing legitimate authentication features rather than exploiting vulnerabilities in the underlying services.
UNC6293 Continues Targeted App Password and OAuth Phishing
UNC6293 was first publicly detailed by Google and Citizen Lab in 2025. GTIG assesses with moderate confidence that the cluster is a sub-cluster of ICE RELIC, Google's tracking name for the activity historically associated with APT29, also known as Cozy Bear and Midnight Blizzard.
The group has historically used highly selective phishing campaigns against individuals considered of interest to Russia. In previous operations, attackers impersonated U.S. State Department officials and attempted to convince victims to create Google application-specific passwords using names such as ms.state.gov.
Application-specific passwords can provide applications or devices with account access without requiring the same authentication flow as a normal login, making them an attractive target for attackers.
UNC6293's campaigns generally remain small, with fewer than five targets in individual operations. The phishing themes frequently involve diplomatic events, conferences, and meetings, giving the malicious communications a plausible context.
By June 2026, GTIG had also observed UNC6293 shifting toward OAuth phishing.
Instead of directly requesting a password, attackers instructed victims to complete a legitimate authentication process and then provide either a verification code or the resulting URL. Once supplied, the information could allow the attacker to gain access to the victim's account.
UNC5976 Uses Fake File-Sharing Pages to Steal OAuth Tokens
UNC5976 represents another authentication-focused cluster that GTIG believes has been active since at least March 2026.
The group has used domains designed to resemble file-sharing services. Attackers create cloud projects associated with these domains and host fake file-sharing pages that eventually display a convincing login prompt.
Victims are presented with a "Continue with Google" button. Rather than sending credentials directly to a fake login page, the button redirects the victim to Google's legitimate OAuth authentication infrastructure.
After successful authentication, the victim is redirected to an attacker-controlled cloud project containing scripts designed to obtain and stage authentication tokens.
Google said UNC5976 created at least 12 domains and associated infrastructure using this technique since March 2026. Google subsequently disrupted those domains, prompting the group to move its phishing infrastructure to other cloud providers.
The technique is particularly difficult for users to identify because the actual authentication step takes place on legitimate Google infrastructure.
UNC5976 Also Targets Aerospace and Defense
UNC5976 has also been linked to malware delivery operations.
One campaign involved a malicious Excel plugin called HEADRUSH, which was used to deliver an HTML Application (HTA). The malware was distributed through a fake website impersonating a Ukrainian research institute.
The activity was potentially aimed at a Ukrainian aerospace and imaging organization, although Google said the complete scope of the operation remains unclear.
The group's broader targeting includes military organizations, aerospace companies, the defense industrial base, NGOs, and think tanks, with Ukraine and Armenia among the geographic areas of particular interest.
UNC7005 Uses WhatsApp Device Linking
The third cluster, UNC7005, has emerged as a major focus of GTIG's latest research.
The group is also tracked as Storm-2945 and was identified by Google in February 2026. Its victims have included academics, diplomats, nonprofit personnel, and researchers in Ukraine, Western Europe, and the United States.
UNC7005 has conducted phishing operations against Microsoft and WhatsApp accounts, as well as Google accounts.
One particularly notable campaign involved abusing WhatsApp's legitimate device-linking functionality.
Attackers created phishing pages that impersonated WhatsApp and offered targets the opportunity to join supposedly secure calls, encrypted chats, or document-sharing sessions.
Victims were first asked to provide their phone number. The attackers then initiated a legitimate WhatsApp device-linking request from an attacker-controlled device.
The phishing page displayed the genuine QR code or linking code and instructed the victim to complete the linking process.
If the victim followed the instructions, the attacker-controlled device could become associated with the victim's WhatsApp account.
Attackers Attempted to Record WhatsApp Calls
The campaign did not necessarily stop after account linking.
Once the attacker's device was successfully linked, the phishing page presented additional options, including joining a voice call, opening an encrypted chat, or downloading a file.
If the victim selected the voice-call option, JavaScript on the malicious page could attempt to record audio and video and transmit the recordings to attacker-controlled infrastructure.
The encrypted-chat option presented another social-engineering step designed to obtain credentials through a secondary URL.
The exact contents of the offered file download were not determined.
The campaign illustrates how attackers can abuse legitimate account functionality without exploiting a vulnerability in WhatsApp itself.
Commodity Infostealers Added to UNC7005 Operations
Around May 2026, UNC7005 also expanded its operations by deploying commodity information-stealing malware.
The group used Vidar and Atomic/AMOS to target Windows and macOS systems belonging to U.S.-based academics, diplomats, and researchers working on Russia and former Soviet states.
Phishing emails directed targets to pages impersonating a summit related to support for Ukraine. Victims were encouraged to download a companion application to access the complete resolution.
This provided attackers with an additional route to obtain information from targeted systems.
Google OAuth Campaign Targets European Defense Organizations
In another campaign beginning in late July and early August 2026, UNC7005 registered domains impersonating Finland's Operations Center, an organization supporting Finnish companies operating in defense and security markets.
Between August 6 and August 13, targeted phishing emails were sent to individuals connected with the European defense industry.
Victims visiting the malicious domain were redirected to Google's legitimate OAuth login page.
After authentication, they were redirected to an attacker-controlled cloud project where scripts attempted to steal authentication tokens.
The technique again demonstrates the central theme of the campaign: attackers are increasingly manipulating legitimate authentication workflows instead of simply collecting usernames and passwords through fake login forms.
CaptiveCrunch Expands the Attack Surface
GTIG's findings also connect UNC7005 activity with a campaign known as CaptiveCrunch, previously documented by Microsoft and ReliaQuest.
CaptiveCrunch targets captive Wi-Fi portals at locations such as:
- Hotels
- Airports
- Conference centers
- Other public networks
Attackers reportedly gain administrative access to Wi-Fi gateways and modify their configurations.
They can then use DNS manipulation to redirect selected web traffic through attacker-controlled infrastructure.
This creates an opportunity to intercept users and present malicious authentication pages while the victim believes they are interacting with a legitimate service.
Microsoft said some of the activity involved domains impersonating Microsoft online services and subsequent adversary-in-the-middle (AitM) phishing targeting Microsoft Entra ID device-code authentication.
Malware Delivered Through Captive Wi-Fi Attacks
The CaptiveCrunch activity can also be used for malware delivery.
One payload identified in the campaign is CornFlake RAT, a Go-based remote access trojan capable of system enumeration, file collection, keylogging, credential and session-token theft, removable-media monitoring, and remote shell access.
Another payload, ChocoShell, is a PowerShell-based information stealer.
ChocoShell has been observed targeting browser session cookies, saved passwords, Microsoft 365 SSO tokens, and Wi-Fi credentials. Researchers also assessed that portions of the malware may have been generated using a large language model.
FruitStone Provides Centralized Command and Control
The campaign uses a centralized web-based command-and-control platform called FruitStone, which is presented under the branding "CloudSync Console" and associated with a fictional or misleading company name, "Acuity Systems, Inc."
Microsoft described FruitStone as a single-page HTML and JavaScript application that provides operators with a centralized interface for managing compromised systems.
The panel reportedly supports functions for:
- Managing compromised endpoints
- Building campaign payloads
- Deploying malware
- Reviewing screenshots
- Collecting keystrokes
- Accessing browser credentials
- Managing stolen information
The panel was reportedly exposed without authentication, potentially providing researchers with visibility into the threat actor's infrastructure.
Possible MSP Supply-Chain Component
Lumen Black Lotus Labs has also raised the possibility that the CaptiveCrunch operation involved compromises of Managed Service Providers (MSPs).
According to the company's assessment, attackers may have compromised MSP environments and then abused trusted relationships with their customers.
Once inside client networks, the attackers could potentially manipulate DNS requests on compromised Wi-Fi infrastructure and redirect travelers toward malicious authentication portals.
The technique would give attackers another route to steal OAuth tokens or deploy information-stealing malware.
A Broader Shift Toward Authentication Abuse
The campaigns demonstrate a significant evolution in targeted phishing.
Rather than simply creating fake login pages and stealing passwords, the attackers are abusing legitimate authentication mechanisms such as:
- Google OAuth
- Google application-specific passwords
- Microsoft device-code authentication
- WhatsApp device linking
- Legitimate cloud infrastructure
- Captive Wi-Fi authentication flows
This makes traditional phishing awareness more difficult because the victim may actually interact with a genuine authentication service.
Google noted that this abuse of legitimate features can make malicious access harder to distinguish from legitimate account activity.
The campaigns also show how attackers are combining account compromise with malware delivery, cloud infrastructure, residential proxies, captive-network manipulation, and social engineering.
Who Is Being Targeted?
The observed targeting spans several high-value categories:
- Academics and researchers
- Diplomats
- Government personnel
- Defense industry employees
- Aerospace organizations
- Think tanks
- Nonprofit organizations
- Researchers focused on Russia and former Soviet states
- Individuals associated with Ukraine and European security
GTIG emphasized that these operations are highly targeted rather than large-scale phishing campaigns. Reporting on the activity indicates that individual campaigns can involve very small numbers of victims, making them less likely to be detected through volume-based phishing defenses.
Key Takeaway
The activity from UNC6293, UNC7005, and UNC5976 highlights how Russian-linked espionage operations are increasingly turning legitimate authentication features into attack mechanisms.
The attackers do not necessarily need to steal a password or exploit a software vulnerability. Instead, they can manipulate users into authorizing attacker-controlled devices, sharing authentication codes, completing legitimate OAuth flows, or accessing malicious infrastructure through trusted network environments.
For organizations and high-value individuals, the key defensive priority is therefore not simply identifying fake login pages, but monitoring for unusual OAuth grants, new device links, suspicious authentication sessions, unexpected account changes, and anomalous use of legitimate cloud services.
Google's latest assessment describes the three clusters as distinct but overlapping in their focus on legitimate authentication workflows, while attribution remains an intelligence assessment rather than proof that every activity described is directly controlled by the same Russian organization