Skip to content
Russian Cyber Espionage Clusters Exploit OAuth and Phishing Techniques

Russian Cyber Espionage Clusters Exploit OAuth and Phishing Techniques

First seen 21 Aug 2026, 00:51 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 22, 2026 at 00:48 UTC
  • •Three Russian cyber espionage clusters are actively targeting sensitive sectors in the U.S. and Europe.
  • •Attack methods include OAuth abuse and app password phishing, making detection challenging.
  • •The operations are highly selective, often involving fewer than 100 targets per campaign.

Google's Threat Intelligence Group (GTIG) is tracking three Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—targeting individuals in academia, defense, and government across Europe and the U.S. These groups exploit legitimate authentication workflows, such as OAuth and app password phishing, to compromise accounts. UNC6293 impersonates U.S. State Department officials, while UNC7005 and UNC5976 employ various social engineering tactics, including fake invitations and device linking. The attacks are highly selective, often targeting fewer than 100 individuals at a time, but they pose significant risks due to their sophisticated methods. GTIG has observed these operations since at least 2025, with ongoing adaptations to their phishing techniques. The current status indicates a persistent threat as these clusters continue to evolve their tactics.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2025-06-01
UNC6293 phishing campaign reported
GTIG reported UNC6293's app password phishing targeting individuals critical of Russia, impersonating State Department officials.
cloud.google.com
2025-10-01
Continued UNC6293 operations observed
GTIG noted UNC6293's ongoing phishing attempts using similar tactics as previously reported, including impersonation of State Department officials.
cloud.google.com
2026-06-01
UNC7005 identified
GTIG first identified UNC7005, linked to APT29, targeting academia and diplomatic personnel with OAuth phishing.
Technadu
2026-08-01
UNC5976 activity reported
GTIG reported UNC5976's use of cloud infrastructure for token theft and deployment of malware against Ukrainian entities.
Technadu
2026-08-21
Current operations detailed
GTIG released a report detailing ongoing phishing campaigns by UNC6293, UNC7005, and UNC5976, emphasizing their evolving tactics.
cloud.google.com

More articles in this cluster (15)

Following this threat?

Track APT29 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed