Russian OAuth Phishing Clusters Target Academia and Defense

Conceptual security image showing OAuth, app password and device linking abuse targeting research and defense accounts.

Google Maps Russian-Nexus Login Phishing Campaigns​

Google Threat Intelligence Group says it is tracking three distinct suspected Russian cyber espionage clusters that abuse legitimate authentication flows rather than relying only on fake login pages. The targets described include people in academia, aerospace and defense, government, diplomacy, nonprofits and think tanks across Europe and the United States. The report matters because app passwords, OAuth consent screens and linked devices can look routine to users while still giving attackers account access.

Google separates three suspected clusters​

GTIG names the clusters as UNC6293, UNC7005 and UNC5976, and assesses with high confidence that all three have a Russian nexus. The assessment is based on targeting patterns, phishing themes and shared operational techniques, rather than a single public indicator.

The groups are not described as identical. GTIG assesses with moderate confidence that UNC6293 and UNC7005 are related to a subcluster of ICE RELIC, formerly APT29, associated with initial access operations. UNC5976 is treated as distinct, with different infrastructure choices and a heavier malware and tooling footprint.

That separation is useful for defenders. If campaigns share themes such as diplomatic invitations or file sharing, but use different infrastructure and account-abuse methods, blocking one domain or one lure is unlikely to address the full risk.


Why legitimate login flows raise the risk​

The common thread across the report is the abuse of real authentication features. GTIG says the clusters use app passwords, OAuth consent flows, device code phishing and messaging-app device linking to obtain access in ways that may not immediately appear fraudulent to a target.

App password phishing is one example. Google says UNC6293 previously impersonated the US State Department and tried to persuade targets to create an app password named ms.state.gov. In later activity, the attacker asked for the app password to be entered into an authentication form on a legitimate-looking site rather than returned by email.

OAuth phishing creates a different problem. A target may complete a real login at a legitimate provider, but then hand over a verification code, full URL or consent grant that enables account access. For organizations, this can be harder to detect than a password typed into a fake page, especially when the targeted account is personal rather than centrally managed.


UNC7005 links phishing, hotels and malware​

UNC7005 is the broadest case in the report. GTIG says the cluster targets academia, diplomatic and nonprofit personnel across Ukraine, Western Europe and the United States, while also conducting device code phishing against Microsoft and WhatsApp accounts.

The group used event and conference themes, including pages spoofing the GLOBSEC forum and invitations to diplomatic events. Google also ties UNC7005 to hospitality captive portal redirects that sent users from hotel and conference-center networks to attacker infrastructure mimicking Microsoft authentication resources. GTIG says it linked that infrastructure to other UNC7005 authentication and malware operations dating back to April 2026.

UNC7005 also moved beyond credential and token theft. In one late May 2026 wave, Google says phishing pages served infostealer malware to Windows or macOS users after presenting a Ukraine-related summit lure. The Windows path involved VIDAR, while the macOS path involved ATOMIC, both described by GTIG as Malware-as-a-Service infostealers that target sensitive browser information.


UNC5976 shows cloud-token automation​

UNC5976 is described as a suspected Russian cyber espionage cluster with an authentication focus that GTIG began tracking in March 2026. Its operations centered on OAuth phishing and automated token collection through abused cloud infrastructure.

Google says UNC5976 bought domains, often with file-sharing themes, then paired them with cloud projects. Targets were shown fake file-sharing pages and, after authentication through a legitimate Google OAuth login page, were redirected to cloud project URLs that hosted scripts to collect authentication tokens.

GTIG says that within approximately three months of discovery and disruption, UNC5976 created at least twelve new domains and related infrastructure. Google says it acted to disable the cloud projects and now assesses that UNC5976 is moving part of its phishing infrastructure away from Google infrastructure to other providers.


Hardening steps focus on consent and devices​

Google says it has disabled known actor accounts where possible, secured victims to remove access to compromised accounts and taken action against infrastructure used to host malicious content. The user-facing guidance is practical: do not proceed past warnings for suspicious websites, check the browser URL before entering credentials or authenticating, and confirm unexpected invitations through official contact details found outside the message.

GTIG says app passwords are not recommended or necessary in most cases and should not be treated as account or identity verification tools. Users who may have created an app password tied to these campaigns are advised to remove it, and high-risk users are pointed toward Google’s Advanced Protection Program. Enterprise Google Cloud customers can restrict App Specific Passwords through stronger 2-Step Verification settings or Advanced Protection enrollment.

For messaging apps, the advice is to harden against device-linking attacks. Google recommends registration locks and two-factor authentication where available, routine reviews of linked devices, and safety-number or safety-code checks over separate communication channels. The implication is clear: account security now extends beyond email inboxes and corporate identity systems.


Conclusion​

GTIG’s report describes an espionage pattern built around trust in familiar login workflows. The campaigns are not limited to one provider, one sector or one lure; they move across OAuth, app passwords, device codes, captive portals, messaging apps and malware delivery.

For high-risk academics, diplomats, defense-sector staff and policy researchers, the main lesson is to treat unexpected authentication requests as sensitive events. A real login page does not guarantee a safe request, and a familiar conference or file-sharing theme can still lead to account compromise if the surrounding invitation cannot be independently verified.


Sources​


Editorial Team - CoinBotLab
  • Reading time 5 min read
  • Views3
  • Reading time 5 min read
  • Views7
  • Reading time 5 min read
  • Views29
  • Reading time 4 min read
  • Views20
  • Reading time 5 min read
  • Views28
  • Reading time 7 min read
  • Views35

Comments

There are no comments to display

Information

Author
CoinBotLab AI Editor
Published
Reading time
5 min read
Views
3

More by CoinBotLab AI Editor

Top