Social engineering landing page used in a UNC7005 operation
At a glance
| Factor | Details |
|---|---|
| Actor or Group | UNC6293, UNC7005 (STORM-2945), and UNC5976 (Suspected Russian nexus) |
| Activity Type | Authentication abuse, OAuth phishing, device code phishing, and captive portal hijacking |
| Targets or Victims | Government, defense, aerospace, academia, and think tanks in Europe and the US |
| Scale | Targeted high-value operations with selective victim pools across multiple nations |
| Status | Active cyber espionage campaigns monitored by industry defenders |
| Source | Google Threat Intelligence Group (GTIG) |
TL;DR
Google Threat Intelligence Group identified three distinct Russian cyber espionage clusters targeting high-profile officials and organizations worldwide. These threat actors bypass traditional login protections by abusing legitimate authentication flows like OAuth and device codes. Consequently, these groups successfully infiltrate accounts without triggering standard credential alerts.
What Happened
Google security researchers observed an aggressive series of account compromise campaigns targeting international policy experts. Specifically, the activity tracks three separate intrusion groups designated as UNC6293, UNC7005, and UNC5976.
According to the analysis by Google Threat Intelligence Group, the attackers focus heavily on subverting native identity platforms. As GTIG noted, “While each group conducts their campaigns differently, they all ultimately demonstrate a focus on abuse of legitimate authentication workflows to compromise accounts.”
UNC6293 Authentication Phishing
The first cluster, UNC6293, conducts highly targeted app password phishing operations. Threat actors create deceptive documents impersonating the United States Department of State. These PDF lures instruct recipients to generate custom application passwords within their personal email accounts.
Originally, the attackers asked victims to return these generated passwords via email. However, newer waves direct targets to submit their credentials directly onto spoofed portals. Furthermore, UNC6293 now deploys OAuth phishing pages that prompt users to paste verification codes from external identity providers.
UNC7005 Multi-Vector Operations
Meanwhile, the UNC7005 cluster uses an even wider array of social engineering vectors. The group sends email invitations spoofing prominent diplomatic conferences such as the GLOBSEC forum. When targets open the link, an automated script fingerprints their browser environment to evade security analysts.
Next, the page presents an elaborate registration form. As GTIG observed, “The registration process is thorough, and notably contains an epicurean wine selection, which was a theme in multiple previous ICE RELIC-linked phishing campaigns.” After registration, the site directs the victim to complete a Microsoft device code authentication flow.
Additionally, UNC7005 conducts device-linking phishing against WhatsApp users. The landing page tricks targets into scanning a QR code to link their account to an attacker device. Once linked, the site triggers malicious JavaScript to record video and microphone audio.
Beyond credential harvesting, UNC7005 distributes information-stealing malware. The group deploys VIDAR for Windows and ATOMIC for macOS disguised as conference companion applications. In hotel and event networks, the operators also hijack captive portals to redirect guests toward malicious login pages.
UNC5976 Cloud Infrastructure Exploitation
The third cluster, UNC5976, abuses cloud services to capture user credentials. Attackers register domains that mimic Google Drive or shared file portals. When visitors open the fake file-sharing page, a popup prompts them to authenticate via Google OAuth.
Upon signing in, the victim redirects to an attacker-controlled cloud project that collects authentication tokens. In separate operations, UNC5976 deployed a malicious Excel add-in named HEADRUSH to compromise Ukrainian aerospace targets.
Who Is Behind It
Google Threat Intelligence Group assesses with high confidence that all three groups possess a Russian nexus. Shared operational themes, geographic targets, and post-compromise behaviors strongly align with Russian strategic priorities.
Specifically, analysts connect two of the clusters directly to known intelligence units. As researchers stated, “We assess with moderate confidence that UNC6293 is a sub cluster of ICE RELIC (formerly APT29) responsible for initial access operations.” UNC7005 also shares significant infrastructure and tactical overlaps with ICE RELIC campaigns.
In contrast, UNC5976 remains distinct from the other two Russian cyber espionage clusters. This group maintains dedicated command infrastructure rather than using residential proxies. Therefore, intelligence analysts assess that UNC5976 likely supports separate Russian state intelligence mandates.
Impact and Scale
These espionage operations target sensitive sectors across Western Europe, Ukraine, Armenia, and the United States. Victims include prominent researchers, government officials, defense contractors, and policy think tanks.
Because the attacks abuse trusted authentication protocols, victims often surrender account tokens without realizing an intrusion occurred. Furthermore, the theft of OAuth tokens and app passwords allows persistent mailbox access without triggering two-factor authentication prompts. When paired with infostealer malware, these campaigns expose proprietary research, internal communications, and diplomatic correspondence.
What Comes Next and Defense Guidance
These suspected Russian cyber espionage clusters will continue adapting their authentication lures. Organizations must educate high-risk employees about the dangers of unsolicited OAuth consent requests and device pairing codes.
First, enterprise administrators should disable user-level app password creation across corporate identity directories. Second, security teams must enforce strict conditional access policies and review third-party OAuth app permissions regularly.
Additionally, users should never scan QR codes or enter device codes from untrusted conference invitations. Whenever possible, organizations should deploy hardware-backed security keys to prevent token theft. By hardening cloud identity settings and monitoring captive portal redirects, enterprises can defend against these aggressive espionage campaigns.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!