Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Russian Snoops Utilize OAuth Abuse in Sophisticated Phishing Campaigns Targeting Academic, Government, and Aerospace Institutions




Russian snoops are using OAuth abuse in targeted phishing campaigns against academic, government, and aerospace institutions. Google has identified three distinct groups, UNC6293, UNC7005, and UNC5976, which have been utilizing various tactics to compromise personal accounts across multiple platforms. The groups' tactics have been highly effective, with the potential to compromise personal accounts across multiple platforms. Individuals in targeted sectors are urged to be vigilant and to recognize malicious outreach to protect themselves from these types of attacks.

  • Google is tracking three suspected Russian cyber-spy groups orchestrating targeted phishing campaigns against academics, aerospace, defense, government agencies, and think tanks in Europe and the US.
  • The groups, identified as UNC6293, UNC7005, and UNC5976, are using tactics such as phishing, OAuth-abuse operations, and device-code phishing to compromise personal accounts.
  • Unclassified, well-funded groups are believed to be behind the attacks, posing a significant threat to targeted sectors.
  • UNC6293, a suspected APT29 group, has been posing as US State Department employees to lure victims into giving them access to their email correspondence.
  • Google is urging individuals in targeted sectors to be vigilant and recognize malicious outreach, and to take steps to protect themselves, including regularly updating software and being cautious when clicking on links or responding to unsolicited emails.



  • In a recent development that has sent shockwaves through the cybersecurity community, Google has revealed that it is tracking three distinct suspected Russian cyber-spy groups that have been orchestrating highly targeted phishing campaigns against individuals in academia, aerospace, defense, government agencies, and think tanks across Europe and the US. These campaigns, which have been ongoing since at least last year, have demonstrated a level of sophistication and adaptability that has left experts warning of potential victims in these sectors.

    The three groups, identified as UNC6293, UNC7005, and UNC5976, have been utilizing various tactics to compromise personal accounts across multiple platforms, including phishing, OAuth-abuse operations, and device-code phishing. While the number of targets in each campaign is relatively small, with fewer than 100 targets and under 10 victims, the threat-intel team warns that these groups are highly organized and well-funded, making them a significant threat to individuals in targeted sectors.

    UNC6293, a suspected APT29 (also known as Cozy Bear or Ice Relic) phishing squad, has been particularly active in this regard. The group has been posing as US State Department employees to lure victims into giving them long-term access to their email correspondence. This tactic has been effective in the past, with the group linked to the 2020 SolarWinds hack, a major cyberattack that compromised multiple government agencies and private sector organizations.

    UNC7005, another suspected Russian group, has also been using sophisticated phishing tactics, including device-code phishing and OAuth-abuse operations. This group has been targeting prominent, mostly US-based academics, diplomats, and researchers whose work focused on Russia and former Soviet states. The group's tactics have included creating fake websites that appear to be legitimate, with specific information about a resolution supporting Ukraine, plus contact details for general questions or tech support.

    The third group, UNC5976, has been utilizing a different approach, buying up several domains with names related to file sharing and then creating a cloud project related to the domain. The domains host a fake file sharing page that prompts users to "Continue with Google" via a popup link. The links take them to a legitimate Google OAuth login page, asks them to sign in, and after authenticating the credentials redirects the victim to a Google Cloud project URL that saves the authentication token for the attacker.

    Google's Threat Intelligence Group (GTIG) has been tracking these groups and warns that they are highly organized and well-funded, making them a significant threat to individuals in targeted sectors. The group's tactics have been highly effective, with the potential to compromise personal accounts across multiple platforms.

    In response to this threat, Google is urging individuals in targeted sectors to be vigilant and to recognize malicious outreach. The group's tactics are designed to appear legitimate, making it difficult for individuals to distinguish between genuine and phishing attempts. As a result, it is essential for individuals to be aware of the risks and to take steps to protect themselves, including regularly updating software and being cautious when clicking on links or responding to unsolicited emails.

    In conclusion, the use of OAuth abuse in sophisticated phishing campaigns by Russian snoops has sent shockwaves through the cybersecurity community. The tactics employed by these groups are highly sophisticated and adaptable, making them a significant threat to individuals in targeted sectors. As a result, it is essential for individuals to be vigilant and to take steps to protect themselves from these types of attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Russian-Snoops-Utilize-OAuth-Abuse-in-Sophisticated-Phishing-Campaigns-Targeting-Academic-Government-and-Aerospace-Institutions-ehn.shtml

  • https://www.theregister.com/security/2026/08/21/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns/5290706

  • https://en.wikipedia.org/wiki/Cozy_Bear

  • https://www.picussecurity.com/resource/blog/apt29-cozy-bear-evolution-techniques


  • Published: Thu Aug 20 20:43:40 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us