Russian Espionage Clusters Abuse Legitimate Authentication Flows

Google Threat Intelligence Group (GTIG) tracks three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—that abuse legitimate authentication flows to target individuals in academia, aerospace and defense, government, and think tanks across Europe and the United States. The clusters employ app-password phishing, device-code phishing, OAuth phishing, and malware deployment, and GTIG warns that these operations rely on legitimate features that may not appear malicious to users.

UNC6293, assessed with moderate confidence as a subcluster of ICE RELIC (formerly APT29) responsible for initial access, was first reported in June 2025 as an app-password phishing campaign against prominent critics of Russia. Attackers impersonating the U.S. State Department convinced targets to create an app password named ms.state.gov and share it back; later operations instead asked targets to enter the password into a legitimate-looking authentication form. Campaigns are small, typically fewer than five users, and use diplomatic themes tied to upcoming conferences. By June 2026, GTIG observed UNC6293 also performing OAuth phishing by requesting a verification code after the target logged into an external provider.

UNC7005 (aka STORM-2945), identified in February 2026, targets academia, diplomatic, and nonprofit personnel in Ukraine, Western Europe, and the U.S. It is also assessed with moderate confidence as an ICE RELIC initial-access cluster, but is tracked separately due to lower sophistication, poor operational security, divergent infrastructure, and malware use. Its app-password phishing uses unique per-target app passwords. It runs device-code phishing for Microsoft and WhatsApp; a GLOBSEC-themed operation used an embassy-vs-GLOBSEC artifact and an ‘epicurean wine selection’ echoing older ICE RELIC campaigns. In WhatsApp device-linking attacks, after the victim links a device, the page offers a fake voice call whose JavaScript records audio/video and uploads it to the attacker’s C2, or offers encrypted-chat and file-transfer lures. In late May 2026, UNC7005 ran a broad malware campaign serving VIDAR on Windows and ATOMIC on macOS from a ‘Summit Companion App’ download. It also conducted OAuth phishing via Google Cloud projects, including a Finnish Operations Center spoof, and infrastructure linked to the hospitality captive-portal redirects reported by Reliaquest and Microsoft. Tooling overlaps include ENGINELIGHT Go malware and the CHERRYPIE PowerShell stealer, which GTIG suspects may be LLM-generated and possibly purchased from MaaS operators.

UNC5976, a distinct cluster tracked since March 2026, focuses on OAuth phishing and automated token collection via cloud projects. It registers file-sharing themed domains, hosts fake file-sharing pages, and after a brief delay shows a ‘Continue with Google’ popup that leads to a legitimate Google OAuth login, then a redirect to an attacker-controlled cloud project that steals the token. After disruption, UNC5976 created at least twelve new domains and is migrating to non-Google providers. It also distributes the HEADRUSH malicious Excel plugin leading to an HTA downloader, observed in April 2026 against a Ukrainian aerospace/imaging company.

GTIG assesses with high confidence that all three clusters have a Russian nexus. UNC6293 and UNC7005 share operational methodologies with historical ICE RELIC phishing from 2021–2024, including themes such as diplomatic invitations and wine references, while UNC5976 is distinct, possibly aligned with a different Russian intelligence service, with a heavier malware footprint and dedicated post-compromise infrastructure rather than residential proxies. GTIG notes that abuse of legitimate authentication features makes tracking access harder, targets are often personal accounts creating a visibility gap for organizations, and encrypted messenger outreach complicates defense. Remediation guidance includes revoking unused app passwords, verifying URLs before authenticating, confirming invitations through official channels, and using Google’s Advanced Protection Program to disable app passwords.

Distinct Clusters Target Individuals of Interest to Russia

View Original