Russian Hackers Weaponize Google OAuth and WhatsApp in Account Hijacks
Three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—have been leveraging legitimate authentication flows to compromise individuals working in academia, aerospace, defense, government, and think tanks across Europe and the United States, according to researchers Gabby Roncone and Wesley Shields at the Google Threat Intelligence Group (GTIG). The clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to hijack personal accounts across multiple platforms while blending in with normal login activity.
UNC6293, assessed as a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear and Midnight Blizzard), has been conducting tightly scoped operations—often targeting fewer than five users at a time—while impersonating State Department officials. The group previously abused Google's application-specific passwords feature and has since pivoted to OAuth phishing, requesting victims share full redirect URLs or verification codes after performing a legitimate login. Lures revolve around diplomatic themes, upcoming conferences, and cross-platform account linking, including WhatsApp. UNC5976, active since at least March 2026, takes a more automated approach: the group purchases file-sharing-themed domains, builds matching Google Cloud projects, and hosts fake sharing pages featuring "Continue with Google" pop-ups. Once a victim authenticates, malicious scripts embedded in the cloud project harvest OAuth tokens from the redirect URL and stage them for later use. Google has disrupted at least 12 such domains and their related infrastructure.
The third cluster, UNC7005, rounds out the activity set and signals how state-sponsored operators are increasingly abusing trust in identity providers rather than chaining software vulnerabilities. Defenders should enforce phishing-resistant MFA (such as hardware security keys), audit OAuth app consents, monitor for suspicious Cloud projects tied to their tenant, and review link-device prompts on messaging platforms like WhatsApp. Individuals can verify whether their credentials have already surfaced in known breaches with an email breach checker, assess exposed browser attributes via a browser fingerprint test, and confirm there are no rogue network intermediaries intercepting OAuth redirects using a VPN/proxy detector.