Russian Hackers Exploit Google OAuth and WhatsApp Linking to Hijack Accounts

0
6

Key Takeaways

  • Three Russian‑linked threat clusters—UNC6293, UNC5976, and UNC7005—are exploiting legitimate authentication mechanisms (app passwords, OAuth, device‑code flow, WhatsApp linking) to steal credentials from high‑value targets in academia, aerospace/defense, government, and think‑tank sectors across Europe and the United States.
  • The groups employ highly selective, socially engineered phishing lures (diplomatic event invitations, wine‑themed messages, fake file‑share pages, and bogus WhatsApp device‑link requests) that persist over months and adapt to defender countermeasures.
  • Infrastructure abuse is common: domains mimicking legitimate services, cloud‑hosted malicious scripts, and rogue Excel plugins (HEADRUSH) are used to harvest tokens and deploy malware such as Vidar, Atomic (AMOS), CornFlake RAT, and ChocoShell.
  • A parallel campaign, CaptiveCrunch, hijacks captive Wi‑Fi portals and managed service providers (MSPs) to conduct adversary‑in‑the‑middle (AitM) attacks, redirecting traffic to attacker‑controlled sites for credential theft and malware distribution.
  • Defenders should monitor for abnormal OAuth consent grants, unexpected device‑link requests on WhatsApp, unusual cloud‑project token usage, and DNS anomalies on captive portals; applying least‑privilege access, MFA enforcement, and regular review of third‑party app permissions can mitigate these threats.

Overview of Russian Cyber Espionage Clusters
Google Threat Intelligence Group (GTIG) has identified three distinct, suspected Russian cyber‑espionage threat clusters that focus on compromising authentication flows. Dubbed UNC6293, UNC7005, and UNC5976, the groups concentrate on individuals working in academia, aerospace and defense, government institutions, and think‑tanks across Europe, as well as academia and think‑tank entities within the United States. Their campaigns are characterized by persistent, adaptive phishing that leverages legitimate platform features—such as application‑specific passwords, OAuth consent screens, and WhatsApp device linking—to evade detection and maintain long‑term access to victim accounts.


UNC6293: Ice Relic Sub‑Cluster Using App‑Password Abuse
UNC6293 was first detailed by Google and Citizen Lab in June 2025 and is assessed as a sub‑cluster of the Ice Relic (formerly APT29) operation, also known as Cozy Bear or Midnight Blizzard. The group initially abused Google’s application‑specific passwords feature to hijack accounts. Since that discovery, UNC6293 has continued to run small‑scale phishing operations—often targeting fewer than five individuals at a time—by impersonating U.S. State Department officials. Lures revolve around diplomatic themes, upcoming conferences, or meetings, with the attackers requesting victims to share either the full OAuth URL or a verification code after a legitimate login to an external provider. Supplying that code enables the threat actor to seize control of the target’s account.


UNC5976: OAuth Phishing via Cloud‑Hosted Fake File‑Share Pages
UNC5976, active since at least March 2026, focuses on harvesting OAuth tokens through automated cloud infrastructure. The group registers domains that sound like file‑sharing services, creates a Google Cloud project tied to each domain, and hosts a counterfeit file‑share page. When a visitor lands on the page for a few seconds, a pop‑up login dialog appears bearing a “Continue with Google” button. Clicking it redirects the user to the genuine Google OAuth login page; after successful authentication, the victim is sent to an attacker‑controlled cloud project URL that runs a script to extract the authentication token from the URL and stage it for later exfiltration. By mid‑2026, UNC5976 had created no fewer than 12 such domains and related infrastructure, all of which Google subsequently disrupted, prompting the group to shift to alternative providers for its phishing pages.


UNC5976’s HEADRUSH Plugin and Regional Focus
In April 2026, UNC5976 was observed distributing a rogue Excel plug‑in codenamed HEADRUSH that downloads an HTML Application (HTA) payload. The malware is delivered via a fake domain impersonating a Ukrainian research institute and has been linked to attempts against a Ukrainian aerospace and imaging company, although the full infection scope remains unclear. Google notes that UNC5976’s operational focus centers on the military, aerospace, defense industrial base, and NGOs/think‑tanks, with most activity directed at Ukraine and Armenia.


UNC7005: Core GTIG Focus and Broad Target Set
UNC7005 (also tracked as Storm‑2945) emerged as the primary subject of GTIG’s research in February 2026. The group predominantly targets academia, diplomatic personnel, and nonprofit workers across Ukraine, Western Europe, and the United States. Like UNC6293, UNC7005 is believed to belong to an Ice Relic sub‑group that specializes in initial access and leans on commercial residential proxies for post‑compromise activities. Its tactics include highly selective app‑password phishing aimed at individuals of interest to the Kremlin, as well as device‑code phishing against Microsoft and WhatsApp accounts.


UNC7005’s Social Engineering Lures: Diplomatic Events, Wine, and WhatsApp
UNC7005’s phishing emails often masquerade as invitations to diplomatic events or conferences, embedding links to attacker‑controlled sites that profile visitors and then ask them to confirm participation while stating preferred main courses and wine choices—a motif traced back to Ice Relic’s “SPIKEDWINE” campaigns from April 2023. In May‑June 2026, the group expanded to WhatsApp, deploying spoofed pages that lure targets into linking their WhatsApp accounts with an attacker‑controlled device under the pretense of joining a secure call, chat, or file share. Once the device is linked, the phishing page prompts the victim to join a voice call (triggering covert audio/video recording via JavaScript), engage in an encrypted chat (forcing the user to copy displayed credentials to a secondary URL), or download a file whose purpose remains undisclosed.

Around the same period, UNC7005 supplemented its toolkit with commodity infostealers Vidar and Atomic (AMOS) delivered via malicious URLs that spoof a “resolution in support of Ukraine” summit, urging U.S.-based academics, diplomats, and researchers focused on Russia and former Soviet states to download a fake companion application.


UNC7005’s Google Account OAuth Phishing and Cloud Abuse
Starting in early August 2026, UNC7005 launched Google account OAuth phishing operations using cloud infrastructure. Between July 31 and August 13, the group registered domains spoofing the legitimate Finnish Operations Center (FOC), which supports Finnish defense and security firms in NATO contexts. Targeted phishing emails directed recipients to these spoofed domains; after navigating to the site, users were redirected to the genuine Google OAuth login page. Successful authentication sent victims to an attacker‑controlled, unverified cloud project where a script harvested authentication tokens, enabling account hijacking. This activity dovetails with the CaptiveCrunch campaign documented by ReliaQuest and Microsoft.


CaptiveCrunch: Wi‑Fi Portal Hijacking and MSP Supply‑Chain Angle
CaptiveCrunch involves compromising captive Wi‑Fi portals found in hotels, conference centers, and airports to stealthily redirect users to attacker‑controlled infrastructure for credential theft. The threat actor gains administrative access to Wi‑Fi gateways, alters configurations, and employs DNS poisoning to reroute legitimate traffic through malicious resolvers. Microsoft observed that part of this activity uses doppelganger domains mimicking Microsoft online services to conduct adversary‑in‑the‑middle (AitM) phishing that abuses the device‑code authentication flow in Microsoft Entra ID.

From its privileged network position, the actor distributes malware posing as browser or operating system updates in response to automated connectivity checks. This can deploy a Go‑based remote access trojan (CornFlake RAT) or a PowerShell payload dubbed ChocoShell (aka CHERRYPIE). CornFlake RAT performs system enumeration, file and keystroke collection, credential and session‑token theft, audio/video surveillance, removable‑media monitoring, and remote‑shell spawning. ChocoShell, a PowerShell‑based infostealer, extracts Chrome app‑bound encryption keys, saved passwords, Microsoft 365 SSO tokens, and Wi‑Fi credentials; evidence suggests it may have been generated by a large language model.

All compromised endpoints are managed via a centralized web‑based command‑and‑control panel called FruitStone, branded as the “CloudSync Console” and associated with the fictitious “Acuity Systems, Inc.” to masquerade as legitimate cloud‑management software. FruitStone provides an unauthenticated dashboard for managing infected hosts, building and deploying new payloads, and reviewing exfiltrated data such as screenshots, keystrokes, and browser credentials.

Lumen Black Lotus Labs’ tracking of CaptiveCrunch raises the possibility of a supply‑chain component: the actor may have compromised several Managed Service Providers (MSPs) and then abused the trust relationship with their clients. Telemetry shows roughly 70 victim IP addresses, with 40 unique IPs issuing DNS requests to the C2 servers—indicating locations where the actor performed enumeration by redirecting DNS queries to its resolvers. Another 30 unique IPs communicated with the AitM infrastructure to harvest tokens, while a single IP interacted with the ChocoShell C2 server, underscoring the multifaceted nature of the operation.


GTIG Assessment and Defensive Implications
GTIG concludes that these Russia‑linked clusters exemplify a creative abuse of legitimate authentication features—app passwords, OAuth consent flows, device‑code mechanisms, and WhatsApp device linking—to bypass traditional security controls. By chaining social engineering with infrastructure abuse (spoofed domains, cloud projects, compromised Wi‑Fi gateways, and MSP supply chains), the actors achieve rapid credential exfiltration and maintain persistent footholds for follow‑on espionage.

Defenders should prioritize monitoring for anomalous OAuth grants, unexpected WhatsApp device‑link requests, irregular cloud‑project token usage, and DNS anomalies on captive portals. Enforcing phishing‑resistant MFA, restricting third‑party app permissions, regularly reviewing linked devices, and applying least‑privilege principles to Wi‑Fi and MSP access can significantly reduce the success rate of these sophisticated campaigns. Continuous threat‑intelligence sharing and timely patching of known abuse vectors remain essential to countering the evolving tactics of UNC6293, UNC5976, and UNC7005.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here