Russian-linked cyber espionage groups are now using convincing fake Google Drive pages and diplomatic-style invitations to steal access to online accounts—without needing victims to download malware. The campaign preys on individuals in academia, think tanks, government-affiliated and defense organizations across the U.S. and Europe. By mimicking real events and institutions, attackers lure targets into legitimate-looking authorization flows, then hijack accounts via consent tokens or active browser sessions.
How the Phishing Works
The operation includes multiple clusters—UNC5976, UNC6293, and UNC7005—identified through DNS record histories, website content, certificates, and visual page similarities. One tactic involves spoofing Google Drive with nearly identical layouts, including a fake favicon and a page titled “My Drive – Google Drive.”
Instead of asking for passwords, the attackers use OAuth phishing and device-code consent flows. When victims grant access via these routes, attackers gain tokens giving entry to cloud files, emails, and contacts—even when victims don’t realize anything was installed.
Diplomatic Themes & Live-Session Tricks
The UNC6293 group themed emails and web pages around foreign policy organizations, using names and visuals aligned with institutions like the Council on Foreign Relations to make phishing attempts feel authentic. Some subdomains redirected to official sites like the U.S. State Department, potentially using Evilginx-style proxy phishing to intercept real login sessions.
UNC7005 meanwhile focused on device-code phishing, sending fake event invitations branding themselves as Microsoft or WhatsApp-related, and even changing event names and deadlines to avoid detection. UNC5976 specialized in OAuth phishing, registering many lookalike domains and registering small technical touches—shared page templates, hosting traits, CSS/header/favicons—to link different sites to the same infrastructure.
Indicators & Defense Measures
Security analysts collected many indicators of compromise (IoCs), including suspicious domains like foreignrelations[.]us, verify-drive[.]com, ms365-live[.]com, linkfileshare[.]net, and IP addresses associated with these domains. They also identified matching CSS hashes, HTTP header signatures, and favicon hashes that helped tie together what attackers had left behind.
To defend against these tactics, experts recommend treating unexpected Drive file-shares, conference-style invites, and device linking emails with suspicion—especially if they come from domains you don’t usually see. Always navigate to services manually rather than clicking embedded links, check what permissions an OAuth request wants, and establish phishing-resistant login flows. Security teams should look closely at consent grants and session behavior for anomalies.
This isn’t just technical trickery—it’s an escalation in how state-aligned hackers are targeting the very way we authenticate. For defenders, that means visibility into OAuth approvals and browsing sessions is more crucial than ever. What to watch next: broader adoption of proxy-style phishing tools, more phishing bait themed around international affairs, and continued exploitation of account-linking mechanics. Every unexpected invite or share could now be a visit from an adversary.