cloud.google.com Russian Cyber Espionage Clusters Exploit OAuth and Phishing Techniques
Article Content
- •Three Russian cyber espionage clusters are actively targeting sensitive sectors in the U.S. and Europe.
- •Attack methods include OAuth abuse and app password phishing, making detection challenging.
- •The operations are highly selective, often involving fewer than 100 targets per campaign.
Google's Threat Intelligence Group (GTIG) is tracking three Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—targeting individuals in academia, defense, and government across Europe and the U.S. These groups exploit legitimate authentication workflows, such as OAuth and app password phishing, to compromise accounts. UNC6293 impersonates U.S. State Department officials, while UNC7005 and UNC5976 employ various social engineering tactics, including fake invitations and device linking. The attacks are highly selective, often targeting fewer than 100 individuals at a time, but they pose significant risks due to their sophisticated methods. GTIG has observed these operations since at least 2025, with ongoing adaptations to their phishing techniques. The current status indicates a persistent threat as these clusters continue to evolve their tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (15)
Following this threat?
Track APT29 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
TeamViewer Issues Urgent Patch for Five High-Severity Vulnerabilities TeamViewer has released a security bulletin on September 29, 2026, addressing five high-severity vulnerabilities in its remote access software, affecting versions prior to 15.82 on Windows, Linux, and macOS. The most flaw, CVE-2026-92370, allows remote attackers to bypass access controls and execute arbitrary code…
Emerging Threats: Authorization Phishing and InstallFix Attacks In 2026, cybersecurity experts have identified two significant attack vectors: authorization phishing and InstallFix. Authorization phishing exploits OAuth mechanisms to obtain access tokens post-login, bypassing traditional MFA protections. This method has gained traction, with numerous kits available for attackers.…