<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns-aajlbxolg" -->

---
title: Russian snoops add OAuth abuse to targeted phishing...
description: Google&#x27;s Threat Intelligence Group is tracking three suspected Russian cyber-espionage clusters (UNC6293, UNC7005, UNC5976) that target academics, diplomats,...
canonical: https://daily.dev/posts/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns-aajlbxolg
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Russian snoops add OAuth abuse to targeted phishing campaigns | daily.dev
og:description: Google&#x27;s Threat Intelligence Group is tracking three suspected Russian cyber-espionage clusters (UNC6293, UNC7005, UNC5976) that target academics, diplomats,...
og:url: https://daily.dev/posts/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns-aajlbxolg
og:image: https://api.daily.dev/og/posts/AAJlBXOLG.png
og:image:alt: Russian snoops add OAuth abuse to targeted phishing campaigns
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Russian snoops add OAuth abuse to targeted phishing campaigns

**[The Register](https://daily.dev/sources/theregister)** · 6 min read · 0 upvotes · 0 comments

## Summary

Google's Threat Intelligence Group is tracking three suspected Russian cyber-espionage clusters (UNC6293, UNC7005, UNC5976) that target academics, diplomats, aerospace, defense, and NGO personnel across Europe and the US. Each campaign has fewer than 100 targets and under 10 victims, but the groups have shifted tactics toward abusing legitimate OAuth authentication flows and device-code phishing, making attacks harder for victims to recognize as malicious. UNC6293, linked to APT29/Cozy Bear (SVR), poses as US State Department staff and now tricks victims into sharing OAuth verification codes. UNC7005 uses device-code phishing, spoofed diplomatic event invites (including a fake GLOBSEC forum page), and WhatsApp-themed social engineering that deploys infostealers and audio/video-recording malware. UNC5976 registers file-sharing lookalike domains that funnel victims through a real Google OAuth login before stealing the resulting auth token via a Google Cloud project.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.theregister.com/security/2026/08/21/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns/5290706>

## Questions this post answers

### How does the UNC6293 OAuth phishing attack trick victims into giving up account access?

UNC6293 asks targets to perform a legitimate login to an external provider and then share either the resulting full URL or the 'verification code' shown afterward. Handing over that code effectively grants the attacker access to the account, since it completes an OAuth or device-code authorization flow on the victim's behalf, as observed by Google's Threat Intelligence Group in June 2026.

_Stay ahead of evolving OAuth phishing tactics by following security research roundups on daily.dev._

### How does the UNC5976 fake file-sharing OAuth phishing scheme work?

UNC5976 buys domains with file-sharing-related names, builds a fake file-sharing page with a 'Continue with Google' popup, and routes victims through a genuine Google OAuth login. After the victim authenticates, they get redirected to a Google Cloud project URL that silently saves the resulting authentication token for the attacker to reuse.

_Developers securing OAuth integrations can track emerging abuse patterns like this via daily.dev._

### What malware payload does UNC7005 deliver through fake WhatsApp voice call invites?

UNC7005 spoofs WhatsApp and invites victims to join a voice call, and doing so triggers malicious JavaScript that records the target's audio and video and uploads it to the attacker's command-and-control server. The same crew also spoofs diplomatic event invitations, such as a fake GLOBSEC forum page, to distribute infostealers to Mac OS and Windows devices.

_Teams tracking nation-state phishing lures like these can follow related security coverage on daily.dev._

## Similar posts on daily.dev

- ['Several dozen' orgs targeted by a new extortion crew](https://daily.dev/posts/several-dozen-orgs-targeted-by-a-new-extortion-crew-hwkvov6ma) · The Register · 0 upvotes · 0 comments
- [Google: New UNC6783 hackers steal corporate Zendesk support tickets](https://daily.dev/posts/google-new-unc6783-hackers-steal-corporate-zendesk-support-tickets-gepqft9l2) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#google](https://daily.dev/tags/google), [#phishing](https://daily.dev/tags/phishing), [#oauth](https://daily.dev/tags/oauth)

[View this post on daily.dev](https://daily.dev/posts/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns-aajlbxolg)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Russian snoops add OAuth abuse to targeted phishing campaigns","url":"https://daily.dev/posts/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns-aajlbxolg","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns-aajlbxolg"},"datePublished":"2026-08-21T00:22:55.521Z","dateModified":"2026-08-21T00:24:20.836Z","description":"Google's Threat Intelligence Group is tracking three suspected Russian cyber-espionage clusters (UNC6293, UNC7005, UNC5976) that target academics, diplomats,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/245aa5587f82f71cf5a1139555dce9e2?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/245aa5587f82f71cf5a1139555dce9e2?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Register","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Register","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/66aa2113fdad463992ffcbf0e8963fda","url":"https://daily.dev/sources/theregister"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns-aajlbxolg","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,google,phishing,oauth","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Register","item":"https://daily.dev/sources/theregister"},{"@type":"ListItem","position":3,"name":"Russian snoops add OAuth abuse to targeted phishing campaigns"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns-aajlbxolg#faq","mainEntity":[{"@type":"Question","name":"How does the UNC6293 OAuth phishing attack trick victims into giving up account access?","acceptedAnswer":{"@type":"Answer","text":"UNC6293 asks targets to perform a legitimate login to an external provider and then share either the resulting full URL or the 'verification code' shown afterward. Handing over that code effectively grants the attacker access to the account, since it completes an OAuth or device-code authorization flow on the victim's behalf, as observed by Google's Threat Intelligence Group in June 2026. Stay ahead of evolving OAuth phishing tactics by following security research roundups on daily.dev."}},{"@type":"Question","name":"How does the UNC5976 fake file-sharing OAuth phishing scheme work?","acceptedAnswer":{"@type":"Answer","text":"UNC5976 buys domains with file-sharing-related names, builds a fake file-sharing page with a 'Continue with Google' popup, and routes victims through a genuine Google OAuth login. After the victim authenticates, they get redirected to a Google Cloud project URL that silently saves the resulting authentication token for the attacker to reuse. Developers securing OAuth integrations can track emerging abuse patterns like this via daily.dev."}},{"@type":"Question","name":"What malware payload does UNC7005 deliver through fake WhatsApp voice call invites?","acceptedAnswer":{"@type":"Answer","text":"UNC7005 spoofs WhatsApp and invites victims to join a voice call, and doing so triggers malicious JavaScript that records the target's audio and video and uploads it to the attacker's command-and-control server. The same crew also spoofs diplomatic event invitations, such as a fake GLOBSEC forum page, to distribute infostealers to Mac OS and Windows devices. Teams tracking nation-state phishing lures like these can follow related security coverage on daily.dev."}}]}
```

