Friday, 21 August 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Russian snoops add OAuth abuse to targeted phishing campaigns

The Register ·
Russian snoops add OAuth abuse to targeted phishing campaigns

Google is tracking three distinct suspected Russian cyber-spy groups that are targeting individuals in academia, aerospace, defense, government agencies, and think tanks across Europe and the US.

The UNC (unclassified) groups, as Google calls them, have been orchestrating these highly targeted campaigns since at least last year, and they remain ongoing.

Some of the phishing and OAuth-abuse operations used in the attack took place this month.

Each campaign had fewer than 100 targets, and under 10 victims, the threat-intel team told The Register.

Despite the small numbers, if you work in government, NGOs, academia, or aerospace, you may be a target, and over the past few months the Russian snoops have adapted their attacks to abuse legitimate authentication flows.

This makes these types of social engineering tactics appear more legitimate – and allows the cyber operatives to compromise personal accounts across multiple platforms, Google warns.

It also means that potential victims may not recognize these as phishing attempts.

Google says it wants to raise awareness about these campaigns “so that targets can more readily recognize malicious outreach.” In other words: don’t blindly trust that calendar invite that purports to come from the US State Department.

UNC6293 The security analysts have been tracking one of the three, UNC6293, for almost two years.

UNC6293 is a suspected APT29 (aka Cozy Bear, which Google now tracks as Ice Relic – insert eyeroll) phishing squad that poses as US State Department employees to lure victims into giving the snoops long-term access to their email correspondence.

APT29 is probably best known for the 2020 SolarWinds hack, and infosec analysts from the UK and US governments, and the private sector, often link it to Russia's Foreign Intelligence Service (SVR).

On Thursday, Google’s Threat Intelligence Group (GTIG) said it's now tracking two other suspected Russian groups, UNC7005 and UNC5976, which also conduct phishing, abuse OAuth flows, and/or deploy malware to these same types of targeted individuals.

Last summer, GTIG documented UNC6293 phishing for app passwords belonging to people who are critical of Russia.

In this campaign, they impersonated State Department personnel, and they’ve continued using that lure while also adding OAuth phishing into their toolkit.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›