Google's Threat Intelligence Group has identified three suspected Russian cyber-espionage groups — UNC6293, UNC7005, and UNC5976 — conducting highly targeted phishing campaigns against individuals in government, academia, aerospace, and think tanks across Europe and the US. The groups, likely linked to Russia's SVR intelligence service, have increasingly abused legitimate OAuth authentication flows to steal account access tokens, making their attacks harder to detect as malicious. Targets are urged to be vigilant about unsolicited calendar invites, conference invitations, and file-sharing requests, which the operatives use as lures to compromise personal and professional accounts.