← BACK TO FEED
RussiaphishingOAuth abuseAPT29cyberespionage

Three Russian Spy Groups Are Running OAuth Phishing Ops Against Western Targets

Google's Threat Intelligence Group has identified three suspected Russian cyber-espionage groups — UNC6293, UNC7005, and UNC5976 — conducting highly targeted phishing campaigns against individuals in government, academia, aerospace, and think tanks across Europe and the US. The groups, likely linked to Russia's SVR intelligence service, have increasingly abused legitimate OAuth authentication flows to steal account access tokens, making their attacks harder to detect as malicious. Targets are urged to be vigilant about unsolicited calendar invites, conference invitations, and file-sharing requests, which the operatives use as lures to compromise personal and professional accounts.

Google's Threat Intelligence Group has been quietly watching three separate suspected Russian espionage outfits run sophisticated phishing campaigns against people in government, academia, defence, aerospace, and NGOs across Europe and the United States. The campaigns are ongoing, some activity was observed this month, and while the target numbers are small, the victims are high-value.

Each campaign typically had fewer than a hundred targets and fewer than ten confirmed victims. Small scale, yes. But if you work in a relevant sector, that's cold comfort.

What makes these campaigns notable isn't just who's being targeted. It's how. All three groups have incorporated OAuth abuse into their toolkits, exploiting legitimate authentication flows to quietly gain persistent access to accounts without victims ever realising they've handed over the keys. A phishing email is one thing. An apparently normal OAuth login prompt is quite another.

UNC6293: The State Department Impersonators

Google has been tracking UNC6293 for nearly two years. The group is believed to be a phishing unit linked to APT29, otherwise known as Cozy Bear, the Russian Foreign Intelligence Service crew responsible for the 2020 SolarWinds compromise. Google now calls APT29 'Ice Relic', which adds nothing except another alias to an already crowded list.

UNC6293's preferred approach is impersonating US State Department personnel to lure targets into surrendering long-term access to their email accounts. They started with app password theft, targeting people known to be critical of Russia. Then they added OAuth phishing to the playbook.

In June 2026, the group was observed running OAuth phishing operations where targets were asked to share either a full redirect URL or a verification code after logging into a legitimate external provider. Hand over that code and you've handed UNC6293 access to your account. Simple, effective, and easy to miss if you're not paying attention.

UNC7005: The Conference Invitations That Aren't

Identified in February, UNC7005 is another suspected APT29-adjacent group, though Google tracks it separately given its lower operational sophistication and sloppier infrastructure. Microsoft tracks this crew as Storm-2945. Reliaquest and Microsoft first flagged it after spotting captive portal attacks at hotels and conference centres delivering infostealers and keyloggers to public Wi-Fi users.

Since then, UNC7005 has branched out into device-code phishing for Microsoft and WhatsApp accounts, alongside more elaborate social engineering. The lures tend to be fake invitations to diplomatic events and conferences. In May, they recycled a website template from an earlier 'embassy invite' operation and redeployed it to spoof the real GLOBSEC forum, a legitimate Eastern European geopolitics conference.

The fake registration site was convincingly detailed. Google's analysts drily noted it included 'an epicurean wine selection,' a recurring quirk across multiple Ice Relic-linked campaigns. Once a victim lands on the site and goes through the fake registration process, their system gets fingerprinted.

In May and June, UNC7005 also ran WhatsApp social engineering attacks that prompted targets to join voice calls or download files. Joining the voice call triggered malicious JavaScript that recorded audio and video and shipped it off to a command-and-control server. What exactly the Russians do with that footage isn't spelled out, but the applications for follow-on social engineering aren't difficult to imagine.

The group also ran what Google described as the broadest phishing wave it had observed from this crew, targeting prominent US-based academics, diplomats, and researchers focused on Russia and the former Soviet states. The site in question was built with genuine attention to detail, including specific text about a Ukraine-related resolution and contact information for 'technical support.' Those contacts went straight to the attackers. Clicking the download button for a 'Summit Companion App' installed infostealers on the victim's Mac or Windows machine.

Since August, the same group has been running OAuth phishing against both Google and Microsoft accounts using cloud infrastructure.

UNC5976: The File-Sharing Lure

The third group, UNC5976, came onto Google's radar in March 2026 and operates somewhat differently. Rather than conference invites or diplomatic impersonation, UNC5976 buys up domains with file-sharing themed names, spins up associated cloud projects, and hosts fake file-sharing pages on them.

Visit one of these pages and you're presented with a 'Continue with Google' button. That takes you to a completely legitimate Google OAuth login page. You authenticate normally. Then you get redirected to a Google Cloud project URL that quietly saves your authentication token for the attacker. Nothing looks wrong because, technically, nothing is wrong until it is.

Google considers UNC5976 distinct from the other two, partly because it uses dedicated post-compromise infrastructure rather than residential proxies, and partly because it deploys more varied tooling. The analysts suggest this might indicate alignment with a different Russian intelligence service rather than the SVR.

Collectively, these three groups represent a deliberate shift in how Russian state-linked actors are running access operations. Rather than blunt credential theft, they're threading themselves into legitimate authentication flows, making their attacks substantially harder to detect and potentially impossible to spot without knowing what to look for. If you received a calendar invite purportedly from the US State Department this month, it might be worth a second look.

READ NEXT
France's Tax Authority Breach: 600,000 Affected, Private Messages IncludedSVR Operatives Are Turning Hotel Wi-Fi Into Malware TrapsPope's Prayer App Exposes 700,000 Users Because Nobody Bothered to Check Auth