Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three Russian cyber espionage clusters (UNC6293, UNC7005, UNC5976) are exploiting legitimate authentication flows including Google OAuth and WhatsApp device linking to compromise accounts of high-value targets UNC7005 conducted sophisticated WhatsApp phishing campaigns in May-June 2026, luring victims into linking their accounts to attacker-controlled devices via fake QR codes and linking codes UNC5976 automated OAuth token theft by hosting fake file-sharing pages on Google Cloud infrastructure,
Analysis
TL;DR
- Three Russian cyber espionage clusters (UNC6293, UNC7005, UNC5976) are exploiting legitimate authentication flows including Google OAuth and WhatsApp device linking to compromise accounts of high-value targets
- UNC7005 conducted sophisticated WhatsApp phishing campaigns in May-June 2026, luring victims into linking their accounts to attacker-controlled devices via fake QR codes and linking codes
- UNC5976 automated OAuth token theft by hosting fake file-sharing pages on Google Cloud infrastructure, redirecting victims through legitimate Google OAuth flows to capture authentication tokens
- All three clusters are linked to Ice Relic (formerly APT29/Cozy Bear/Midnight Blizzard), with UNC6293 and UNC7005 specifically identified as sub-groups focused on initial access operations
- Targets include individuals in academia, aerospace, defense, governments, and think tanks across Europe and the U.S., with geographic focus on Ukraine and Armenia
Why It Matters
This report highlights an escalating trend of nation-state actors weaponizing legitimate authentication mechanisms—OAuth flows and device linking features—rather than relying solely on traditional phishing, making detection significantly harder for security teams. For AI and cybersecurity practitioners, it underscores the critical importance of monitoring authentication anomalies and implementing multi-factor verification for high-value accounts, as these attacks bypass conventional perimeter defenses by operating within trusted authentication protocols.
Technical Details
- OAuth Token Theft (UNC5976): The group purchased file-sharing-related domains, hosted fake file-sharing pages on Google Cloud projects, and deployed pop-up login dialogs that redirected victims to legitimate Google OAuth pages. Upon authentication, victims were routed to attacker-controlled Google Cloud URLs hosting malicious scripts that extracted authentication tokens from the URL.
- WhatsApp Device Linking Attack (UNC7005): Attackers spoofed WhatsApp to request victims' phone numbers, then initiated legitimate device link requests from attacker-controlled devices. Victims were shown real QR codes and linking codes, and after successful linking, were presented with prompts to join voice calls, encrypted chats, or download files—voice call participation triggered JavaScript to record audio/video and exfiltrate to C2 endpoints.
- Device Code Phishing (UNC7005): Targeted both Microsoft and WhatsApp accounts using diplomatic event invitations as lures, with pages profiling visitors and requesting conference participation details including meal preferences.
- App Password Phishing (UNC6293): Small-scale campaigns targeting fewer than five users at a time, impersonating State Department officials with diplomatic-themed application names and conference-related lures.
- Malware Delivery (UNC5976): Deployed a rogue Excel plugin codenamed HEADRUSH to deliver HTML Application (HTA) payloads, distributed via fake domains impersonating Ukrainian research institutes since April 2026.
Industry Insight
- Organizations should implement behavioral monitoring for OAuth token generation and device linking events, particularly for accounts belonging to personnel in defense, academia, and government sectors who are prime targets for espionage campaigns.
- Security awareness programs must evolve beyond traditional phishing education to include training on recognizing device linking and OAuth authorization requests, as these attacks exploit legitimate platform features rather than deceptive links alone.
- The pivot by UNC5976 from Google Cloud to other providers after infrastructure disruption demonstrates the need for continuous monitoring across all cloud platforms and rapid threat intelligence sharing to stay ahead of adaptive threat actors.
Disclaimer: The above content is generated by AI and is for reference only.