Google's Threat Intelligence Group is tracking three suspected Russian cyber-espionage clusters (UNC6293, UNC7005, UNC5976) that target academics, diplomats, aerospace, defense, and NGO personnel across Europe and the US. Each campaign has fewer than 100 targets and under 10 victims, but the groups have shifted tactics toward abusing legitimate OAuth authentication flows and device-code phishing, making attacks harder for victims to recognize as malicious. UNC6293, linked to APT29/Cozy Bear (SVR), poses as US State Department staff and now tricks victims into sharing OAuth verification codes. UNC7005 uses device-code phishing, spoofed diplomatic event invites (including a fake GLOBSEC forum page), and WhatsApp-themed social engineering that deploys infostealers and audio/video-recording malware. UNC5976 registers file-sharing lookalike domains that funnel victims through a real Google OAuth login before stealing the resulting auth token via a Google Cloud project.

6m read timeFrom theregister.com
Post cover image
Table of contents
UNC6293UNC7005AWS catches Russia's Cozy Bear clawing at Microsoft credentialsRussian spies use remote desktop protocol files in unusual mass phishing driveAttacker phished way into US defense supplier's Microsoft 365 accountRussian spies turn public Wi-Fi into malware delivery systemsUNC5976

Questions this post answers

How does the UNC6293 OAuth phishing attack trick victims into giving up account access?

UNC6293 asks targets to perform a legitimate login to an external provider and then share either the resulting full URL or the 'verification code' shown afterward. Handing over that code effectively grants the attacker access to the account, since it completes an OAuth or device-code authorization flow on the victim's behalf, as observed by Google's Threat Intelligence Group in June 2026. Stay ahead of evolving OAuth phishing tactics by following security research roundups on daily.dev.

How does the UNC5976 fake file-sharing OAuth phishing scheme work?

UNC5976 buys domains with file-sharing-related names, builds a fake file-sharing page with a 'Continue with Google' popup, and routes victims through a genuine Google OAuth login. After the victim authenticates, they get redirected to a Google Cloud project URL that silently saves the resulting authentication token for the attacker to reuse. Developers securing OAuth integrations can track emerging abuse patterns like this via daily.dev.

What malware payload does UNC7005 deliver through fake WhatsApp voice call invites?

UNC7005 spoofs WhatsApp and invites victims to join a voice call, and doing so triggers malicious JavaScript that records the target's audio and video and uploads it to the attacker's command-and-control server. The same crew also spoofs diplomatic event invitations, such as a fake GLOBSEC forum page, to distribute infostealers to Mac OS and Windows devices. Teams tracking nation-state phishing lures like these can follow related security coverage on daily.dev.

1 Impression