Russian Cyber Espionage Groups Target Academia and Government via OAuth Abuse

Russian Cyber Espionage Groups Target Academia and Government via OAuth Abuse

First seen 21 Aug 2026, 00:51 UTC Theregistercloud.google.com 86% similarity 75.5

Article Content

Browse articles
ThreatCluster

Google's Threat Intelligence Group is monitoring three suspected Russian cyber espionage clusters, including UNC6293, UNC7005, and UNC5976, which are targeting individuals in academia, aerospace, defense, and government sectors across Europe and the US. These groups are employing sophisticated phishing techniques that exploit legitimate OAuth authentication flows, making their attacks appear more credible. The campaigns have been ongoing since at least June 2025, with UNC6293 continuing to impersonate US State Department officials to lure victims into providing app passwords. Recent operations have adapted to include requests for verification codes after legitimate logins, further complicating detection. Each campaign typically targets fewer than 100 individuals, with under 10 confirmed victims. Google aims to raise awareness of these tactics to help potential victims recognize malicious outreach.

Key Points: • Three Russian cyber espionage groups are targeting academia and government sectors. • Phishing campaigns exploit OAuth flows, making them harder to detect. • UNC6293 has been active since June 2025, impersonating US State Department officials.

ThreatCluster AI How this analysis works

Timeline

2025-06-01
UNC6293 phishing operations reported
UNC6293 began aggressive app password phishing campaigns targeting individuals critical of Russia, impersonating State Department officials.
cloud.google.com
2025-10-01
Continued UNC6293 phishing observed
GTIG noted UNC6293 using the same lure document to target victims, maintaining its impersonation tactics.
cloud.google.com
2026-06-01
OAuth phishing tactics introduced
GTIG observed UNC6293 requesting verification codes from targets after legitimate logins, marking a shift in their phishing strategy.
Theregister
2026-08-21
Current monitoring of Russian clusters
Google is actively tracking UNC6293, UNC7005, and UNC5976, which continue to target individuals in sensitive sectors.
cloud.google.com

Community

Browse all →