Russian espionage groups expand phishing attacks with OAuth token theft
Google says three suspected Russian cyber-spy clusters are running small-scale, highly targeted phishing campaigns that now exploit OAuth authentication flows.
Google’s Threat Intelligence Group has been monitoring three separate Russian espionage units—UNC6293, UNC7005 and UNC5976—since at least last year, all of which focus on individuals in academia, aerospace, defence, government and think-tanks across Europe and the United States. The campaigns are small, with fewer than 100 targets per operation and under ten successful intrusions, yet they now incorporate OAuth-based phishing to harvest long-term authentication tokens.
UNC6293, linked to the APT29/Cozy Bear group, pretends to be U.S. State Department staff and asks victims to share verification codes after a legitimate login. UNC7005, assessed with moderate confidence as another APT2-related crew, uses fake diplomatic event invitations and device-code phishing for Microsoft and WhatsApp accounts, even deploying malware that records audio and video via malicious JavaScript. UNC5976 creates counterfeit file-sharing sites that prompt users to “Continue with Google,” capturing OAuth tokens through a legitimate Google login page. Google cautions that these tactics blend with genuine authentication flows, making them difficult for potential victims to recognize as malicious.
Why it matters
The new OAuth tricks let Russian spies silently hijack accounts of high-value professionals, increasing the risk of data theft and further espionage.
In this story
