Newly uncovered espionage activity links at least three Russian-aligned hacking groups—UNC6293, UNC5976, and UNC7005—with campaigns that abuse legitimate authentication tools like Google OAuth and WhatsApp device linking to compromise high-value accounts.
Google’s Threat Intelligence Group (GTIG) has flagged actors targeting individuals in the U.S. and Europe who work in academia, defense, government, and policy think tanks. These groups are deploying adaptable phishing strategies and social engineering to take control of personal and professional accounts. UNC6293 (part of Ice Relic, also known as Cozy Bear or Midnight Blizzard), UNC5976, and the recently profiled UNC7005 are at the heart of these efforts. ([thehackernews.com](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html))
How the Attackers Are Operating
UNC6293 is using application-specific password phishing, particularly impersonating U.S. State Department officials with themes tied to diplomatic meetings and events. In June 2026, this group escalated to OAuth phishing, tricking targets into giving up verification codes or other sensitive info after a legitimate login, letting attackers hijack Google accounts. ([thehackernews.com](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html))
UNC5976, active since March 2026, has been creating fake domains (often mimicking file-sharing services) and setting up cloud projects tied to those domains. They lure victims with “Continue with Google” prompts which lead through proper login flows to malicious scripts that steal authentication tokens once victims land on attacker-controlled infrastructure. ([thehackernews.com](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html))
UNC7005: A Multi-Modal Threat]
Identified earlier this year as deeply tied to initial access operations in Ice Relic, UNC7005 has developed a host of phishing and malware tactics. They’ve used device code phishing to compromise Microsoft and WhatsApp accounts, often sending bait themed around diplomatic events. In mid-2026, the group began sophisticated WhatsApp account compromise flows. Targets are misled into linking their WhatsApp account to a device controlled by attackers. Once linked, victims may be prompted to join a secure voice call, chat, or download a file—all of which enable the attackers to capture video, audio, credentials, or additional illicit access. ([thehackernews.com](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html))
To add to their arsenal, UNC7005 has deployed commodity infostealers such as Vidar and Atomic (aka AMOS), with some malware lures spoofing a Ukrainian research institute. Recent operations include Google OAuth phishing using cloud infrastructure under domains that impersonate the Finnish Operations Center, targeting entities within the European defense sector. ([thehackernews.com](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html))
Capsule Attacks & Supply Chain Concerns
Another major campaign called CaptiveCrunch is being linked to these operations. It includes Wi-Fi gateway manipulations in hotels, airports, and conference centers to redirect users through infrastructure that steals credentials or OAuth tokens. Threat actors are also creating doppelgänger domains that mimic Microsoft services to conduct adversary-in-the-middle phishing attacks and distribute malware disguised as system or browser updates. ([thehackernews.com](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html))
More alarmingly, there’s emerging evidence this supply chain includes managed service providers (MSPs). The actors appear to use compromised MSPs to stage attacks—redirecting DNS requests or deploying infostealers—against users visiting known travel or conference locations. ([thehackernews.com](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html))
These campaigns show a sophisticated abuse of legitimate feature sets—app passwords, device linking, OAuth flows—making malicious account takeovers harder to detect. Rapid token exfiltration and abuse of genuine accounts for follow-up phishing amplify risk. ([thehackernews.com](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html))
Why this matters: By turning trusted tools into attack vectors, these threat actors erode foundational security assumptions. Users and organizations must scrutinize when “official” OAuth prompts, app password requests or device linking flows appear—and consider deploying stronger multi-factor or behavioral signals. Look out for suspicious domains, unusual cloud project activity and phishing messages themed around diplomatic or high-profile events. What you do now can define whether tomorrow’s credential remains yours.