AI Security AI安全 1d ago Updated 1d ago 更新于 1天前 43

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts 疑似俄罗斯黑客滥用Google OAuth和WhatsApp链接劫持账户

Three Russian cyber espionage clusters (UNC6293, UNC7005, UNC5976) are exploiting legitimate authentication flows including Google OAuth and WhatsApp device linking to compromise accounts of high-value targets UNC7005 conducted sophisticated WhatsApp phishing campaigns in May-June 2026, luring victims into linking their accounts to attacker-controlled devices via fake QR codes and linking codes UNC5976 automated OAuth token theft by hosting fake file-sharing pages on Google Cloud infrastructure, 三个俄罗斯网络间谍组织(UNC6293、UNC7005、UNC5976)利用Google OAuth和WhatsApp设备链接等合法认证流程,针对欧美及乌克兰的学术界、航空航天、国防和政府人员实施定向账户劫持 UNC6293(Ice Relic/APT29子集群)采用小规模精准钓鱼,伪装国务院官员诱导受害者提供应用专用密码,2026年6月已转向OAuth钓鱼攻击 UNC5976通过购买文件共享类域名搭建虚假登录页面,利用Google Cloud项目托管恶意脚本自动窃取OAuth令牌,已创建至少12个基础设施节点 UNC7005(Storm-2945)结合设备码钓鱼和WhatsApp链接攻击,通

65
Hot 热度
65
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • Three Russian cyber espionage clusters (UNC6293, UNC7005, UNC5976) are exploiting legitimate authentication flows including Google OAuth and WhatsApp device linking to compromise accounts of high-value targets
  • UNC7005 conducted sophisticated WhatsApp phishing campaigns in May-June 2026, luring victims into linking their accounts to attacker-controlled devices via fake QR codes and linking codes
  • UNC5976 automated OAuth token theft by hosting fake file-sharing pages on Google Cloud infrastructure, redirecting victims through legitimate Google OAuth flows to capture authentication tokens
  • All three clusters are linked to Ice Relic (formerly APT29/Cozy Bear/Midnight Blizzard), with UNC6293 and UNC7005 specifically identified as sub-groups focused on initial access operations
  • Targets include individuals in academia, aerospace, defense, governments, and think tanks across Europe and the U.S., with geographic focus on Ukraine and Armenia

Why It Matters

This report highlights an escalating trend of nation-state actors weaponizing legitimate authentication mechanisms—OAuth flows and device linking features—rather than relying solely on traditional phishing, making detection significantly harder for security teams. For AI and cybersecurity practitioners, it underscores the critical importance of monitoring authentication anomalies and implementing multi-factor verification for high-value accounts, as these attacks bypass conventional perimeter defenses by operating within trusted authentication protocols.

Technical Details

  • OAuth Token Theft (UNC5976): The group purchased file-sharing-related domains, hosted fake file-sharing pages on Google Cloud projects, and deployed pop-up login dialogs that redirected victims to legitimate Google OAuth pages. Upon authentication, victims were routed to attacker-controlled Google Cloud URLs hosting malicious scripts that extracted authentication tokens from the URL.
  • WhatsApp Device Linking Attack (UNC7005): Attackers spoofed WhatsApp to request victims' phone numbers, then initiated legitimate device link requests from attacker-controlled devices. Victims were shown real QR codes and linking codes, and after successful linking, were presented with prompts to join voice calls, encrypted chats, or download files—voice call participation triggered JavaScript to record audio/video and exfiltrate to C2 endpoints.
  • Device Code Phishing (UNC7005): Targeted both Microsoft and WhatsApp accounts using diplomatic event invitations as lures, with pages profiling visitors and requesting conference participation details including meal preferences.
  • App Password Phishing (UNC6293): Small-scale campaigns targeting fewer than five users at a time, impersonating State Department officials with diplomatic-themed application names and conference-related lures.
  • Malware Delivery (UNC5976): Deployed a rogue Excel plugin codenamed HEADRUSH to deliver HTML Application (HTA) payloads, distributed via fake domains impersonating Ukrainian research institutes since April 2026.

Industry Insight

  • Organizations should implement behavioral monitoring for OAuth token generation and device linking events, particularly for accounts belonging to personnel in defense, academia, and government sectors who are prime targets for espionage campaigns.
  • Security awareness programs must evolve beyond traditional phishing education to include training on recognizing device linking and OAuth authorization requests, as these attacks exploit legitimate platform features rather than deceptive links alone.
  • The pivot by UNC5976 from Google Cloud to other providers after infrastructure disruption demonstrates the need for continuous monitoring across all cloud platforms and rapid threat intelligence sharing to stay ahead of adaptive threat actors.

TL;DR

  • 三个俄罗斯网络间谍组织(UNC6293、UNC7005、UNC5976)利用Google OAuth和WhatsApp设备链接等合法认证流程,针对欧美及乌克兰的学术界、航空航天、国防和政府人员实施定向账户劫持
  • UNC6293(Ice Relic/APT29子集群)采用小规模精准钓鱼,伪装国务院官员诱导受害者提供应用专用密码,2026年6月已转向OAuth钓鱼攻击
  • UNC5976通过购买文件共享类域名搭建虚假登录页面,利用Google Cloud项目托管恶意脚本自动窃取OAuth令牌,已创建至少12个基础设施节点
  • UNC7005(Storm-2945)结合设备码钓鱼和WhatsApp链接攻击,通过伪造会议邀请诱导受害者扫描二维码,成功链接后可劫持语音通话并窃取音视频数据
  • 攻击者持续演化技术手法,从应用专用密码钓鱼转向OAuth令牌窃取和WhatsApp设备链接,反映高级威胁组织对认证机制的针对性研究

为什么值得看

本文揭示了国家级黑客组织如何将合法认证功能(OAuth、设备链接)转化为攻击向量,展示了社会工程技术与自动化基础设施结合的现代网络间谍活动模式。对AI从业者而言,理解这些攻击链有助于优化身份验证系统的安全设计,特别是在多因素认证和第三方集成场景下的风险防控。

技术解析

  • OAuth钓鱼技术:UNC5976创建虚假文件共享页面,当用户点击"Continue with Google"后重定向至合法OAuth登录流程,认证成功后跳转至攻击者控制的Google Cloud项目URL,通过恶意脚本从URL中提取认证令牌并暂存备用
  • WhatsApp设备链接劫持:攻击页面要求输入电话号码后,自动生成合法的WhatsApp设备链接请求,向受害者展示真实QR码和链接码,成功链接后诱导加入语音通话,触发JavaScript录音录像并发送至C2服务器
  • 基础设施运营:UNC5976自2026年3月起注册至少12个文件共享类域名,初期使用Google Cloud托管钓鱼页面,在被Google干扰后转向其他云服务商,体现快速迭代的基础设施管理能力
  • 社会工程战术:攻击者使用外交会议邀请、葡萄酒偏好调查等主题诱饵(延续自2023年"SPIKEDWINE"行动),针对特定行业人员设计个性化钓鱼内容,提高受害者信任度和点击率
  • 恶意软件分发:UNC5976通过伪装乌克兰研究机构的域名分发名为HEADRUSH的恶意Excel插件,用于投递HTML Application(HTA)下载,可能针对乌克兰航空航天和成像公司

行业启示

  • 认证机制安全重构:OAuth和设备链接等便捷认证功能需增加二次验证环节,特别是对于高价值目标账户,应实施异常登录检测和会话绑定技术
  • 定向威胁情报共享:针对学术界、国防和政府的APT攻击呈现高度专业化特征,行业间需建立更紧密的威胁情报共享机制,及时更新钓鱼域名和攻击模式数据库
  • 用户安全意识升级:即使来自看似可信来源的会议邀请或文件共享链接也需验证,组织应定期开展针对高级钓鱼技术的培训,强调不随意授权第三方应用访问敏感账户

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究