Skip to content
GTIG Tracks Three Russian Espionage Clusters Abusing Auth Flows

GTIG Tracks Three Russian Espionage Clusters Abusing Auth Flows

Technadu August 21, 2026

Three cyberespionage clusters abuse legitimate authentication workflows to compromise personal accounts. Targets span academia, aerospace and defense, governments, and think tanks across Europe and the U.S. Researchers are highly confident that all three clusters have a Russian nexus, based on shared targeting patterns, phishing themes, and operational techniques.

Google Threat Intelligence Group (GTIG) is tracking them as the UNC6293, UNC7005, and UNC5976 distinct groups focusing on targets of interest to Russia rather than one unified operation.

According to a August 20 report, GTIG assesses with moderate confidence that UNC6293 and UNC7005 are initial access clusters tied to ICE RELIC ( formerly APT29 ).

UNC6293 impersonates U.S. State Department officials in app password phishing , using lures referencing ms.state.gov (and later incorporating OAuth phishing) where the group once asked victims to email their app password back.

Newer operations ask victims to type it directly into a fake authentication form on a convincing lookalike website. Its campaigns tend to be small, usually targeting fewer than five people at a time. In June, the APT targeted prominent British expert on Russian information operations Keir Giles .

UNC7005 (aka STORM-2945), first identified in February 2026, conducts app password, device code, and OAuth phishing , spoofing the GLOBSEC forum and the Finnish Operations Center (FOC), which supports Finnish defense and security firms in the NATO context .

UNC7005 lured targets into linking WhatsApp accounts to attacker devices, then triggered JavaScript to secretly record audio and video during what appeared to be a normal voice call.

The recording uploaded to the attacker's server the moment the "call" was made to look like it failed.

Its broader phishing wave delivered VIDAR to Windows victims and ATOMIC (Atomic Stealer) to macOS users, both malware-as-a-service (MaaS) infostealers that harvest browser-stored credentials, payment information, and cookies.

GTIG also links the group to ENGINELIGHT malware and the LLM-generated CHERRYPIE (ChocoShell) infostealer – researchers found the malware's source code contained unusually prolific function and structure consistent with AI -assisted generation.

UNC5976, a distinct cluster active since at least March 2026 and focused heavily on Ukraine and Armenia, abused Supabase and Cloudflare Workers -style cloud infrastructure for token theft and deployed the HEADRUSH Excel plugin against a Ukrainian aerospace and imaging company.

GTIG added attacker infrastructure to Safe Browsing and disabled malicious cloud projects. Yet, after GTIG's initial disruption, UNC5976 registered at least a dozen new domains within roughly three months and appears to be migrating away from Google-hosted infrastructure entirely in response.

Organizations and high-risk individuals relying on these applications should continue to harden defenses:

ReliaQuest and Microsoft previously reported the hospitality captive portal redirects tied to UNC7005, which GTIG confirmed shares infrastructure and attacker email addresses with the group's broader phishing and malware operations dating back to April 2026.