
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working
Key Highlights
- "Implemented as a single-page application (HTML and JavaScript) serving as the front-end of the C2 server with all functionality exposed without authentication, FruitStone provides a centralized dashboard for managing compromised endpoints, building and deploying new campaign payloads, and reviewing all collected data (such as screenshots, keystrokes, browser credentials)," Microsoft said.
- "Once in client networks, they could target travelers by hijacking DNS requests on a compromised WIFI router; the victims were redirected to spoofed authentication portals to harvest OAuth tokens, or the actor deployed an infostealer," the company said in a report shared with The Hacker News.
- "To perform these OAuth phishing campaigns, UNC5976 purchased domains, usually using file-sharing-related domain names, and then created a cloud project related to that domain," GTIG said.
- "Its operational focus is primarily centered on the military, aerospace, defense industrial base, and NGOs/think tanks," Google said.
- "In May and June 2026, UNC7005 conducted social engineering operations spoofing WhatsApp," Google said.
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.
S.
These clusters include UNC6293, UNC7005, and UNC5976.
"These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms," Google Threat Intelligence Group (GTIG) researchers Gabby Roncone and Wesley Shields said in a report published today.
UNC6293, first detailed by the tech giant and the Citizen Lab in June 2025, is assessed to be a sub-cluster of Ice Relic (formerly APT29), which is also tracked under the monikers Cozy Bear and Midnight Blizzard.
The hacking crew was previously attributed to a campaign that abused a Google account feature called application specific passwords to seize control of victim accounts.
Since then, the threat actor has continued to engage in phishing campaigns that tend to be small in scope, targeting fewer than five users at a time, while impersonating State Department officials to perform app password phishing.
The application names and lures revolve around diplomatic themes and upcoming conferences or meetings, some of which were highlighted by Volexity in December 2025.
As recently as June 2026, Google said it observed the threat actor conducting OAuth phishing by requesting targets to share either the full URL or verification code after performing a legitimate login to an external provider.
Once the requested verification code is provided, it allows the attackers to access the target's account.
UNC5976, the second threat group with an authentication focus, has been found to use OAuth phishing techniques and automate the collection of tokens by abusing cloud infrastructure.
The adversary is believed to be active since at least March 2026.
"To perform these OAuth phishing campaigns, UNC5976 purchased domains, usually using file-sharing-related domain names, and then created a cloud project related to that domain," GTIG said.
"These domains host a fake file sharing page.
After a target visits the page for a few seconds, the page displays a pop-up login dialog.
" The pop-up features a "Continue with Google" button that, if clicked, redirects the victim to the legitimate Google OAuth login page, asking them to sign in to continue.
These clusters include UNC6293, UNC7005, and UNC5976.
The threat actor is estimated to have created no less than 12 new domains and related infrastructure since March 2026, all of which have since been disrupted by Google. The actions are said to have prompted UNC5976 to pivot away from Google infrastructure to other providers to host their phishing pages.
In addition, UNC5976 has been observed leveraging a rogue Excel plugin codenamed HEADRUSH that's used to deliver an HTML Application (HTA) downloaded. The malware, discovered in April 2026, is distributed via a fake domain impersonating a Ukrainian research institute. There are indications that the artifact may have been used to target a Ukrainian aerospace and imaging company, although the full scope of the infection remains unknown.
Originally reported by The Hacker News. TechVeb news desk.
Stay in the loop
Get the latest tech news and AI insights delivered to your inbox. No spam, unsubscribe anytime.
TechVeb Team
Your trusted source for the latest in technology, AI innovations, and digital trends. We bring you in-depth analysis, expert reviews, and comprehensive guides.
Learn more about us →More cybersecurity News
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal securit
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in ques


