oauth abuse2 articles
Three Russian Spy Groups Are Running OAuth Phishing Ops Against Western Targets
Google's Threat Intelligence Group has identified three suspected Russian cyber-espionage groups — UNC6293, UNC7005, and UNC5976 — conducting highly targeted phishing campaigns against individuals in government, academia, aerospace, and think tanks across Europe and the US. The groups, likely linked to Russia's SVR intelligence service, have increasingly abused legitimate OAuth authentication flows to steal account access tokens, making their attacks harder to detect as malicious. Targets are urged to be vigilant about unsolicited calendar invites, conference invitations, and file-sharing requests, which the operatives use as lures to compromise personal and professional accounts.
ToddyCat's Umbrij Malware Quietly Hijacks Gmail via OAuth Abuse
The ToddyCat APT group has developed a new malware called Umbrij that exploits OAuth 2.0 and the Google API to covertly access victims' Gmail accounts. The tool works by launching a Chromium-based browser in headless mode, hijacking an active Gmail session via remote debugging, and using Puppeteer to automate the OAuth authorization process — ultimately obtaining an access token granting full access to Gmail, Drive, Contacts, and other Google services. Organizations are advised to check for unauthorized OAuth app connections, particularly those named "Google Workspace Migration/Sync for Microsoft Outlook," and revoke any suspicious access tokens.