Friday, September 11, 2026

Russia-Linked Hackers Exploit Legitimate Login Flows to Bypass 2FA and Steal Account Access

Three suspected Russian cyber espionage clusters abusing legitimate authentication mechanisms to hijack accounts belonging to academics, diplomats, defense personnel, government staff, and think-tank researchers across Europe and the United States.

Rather than relying solely on credential-harvesting pages, the operators manipulate users into completing genuine app-password, OAuth, device-code, and device-linking workflows that can hand attackers authenticated access despite multi-factor authentication protections.

GTIG assesses with high confidence that the activity has a Russian nexus, while UNC6293 and UNC7005 are assessed with moderate confidence to be initial-access subclusters associated with ICE RELIC, Google’s designation for the actor widely known as APT29.

UNC6293, first publicly detailed in June 2025, has repeatedly impersonated U.S. State Department officials to target prominent individuals critical of Russia.

Its core technique is app-password phishing: victims are instructed to generate an application-specific password often under a deceptive name such as “ms.state.gov” then provide that password to the attacker.

App passwords are designed for legacy applications that cannot support 2FA, meaning a stolen code can enable mailbox access without triggering the victim’s second authentication factor.cloud.

The group has since expanded into OAuth phishing. In June 2026, GTIG observed UNC6293 asking targets to complete a legitimate third-party login and submit the resulting full URL or “verification code” to a phishing site.

Supplying the value effectively grants the adversary authorization to access the victim’s account, turning a real authentication journey into the compromise mechanism.

UNC7005, also known as STORM-2945, has operated since at least February 2026 and targets academic, diplomatic, nonprofit, and defense-related personnel in Ukraine, Western Europe, and the U.S.

Its campaigns have used spoofed conference and embassy invitations to drive victims through Microsoft device-code authentication, where a legitimate Microsoft workflow is repurposed to bind the victim’s account to attacker-controlled access.

GTIG said the group fingerprints visitors and deploys anti-analysis checks on lure sites, indicating active efforts to filter security researchers and automated scanners.


Social engineering landing page used in a UNC7005 operation (Source : GTIG).
Social engineering landing page used in a UNC7005 operation (Source : GTIG).

GTIG Researchers tracked, UNC6293, UNC7005, and UNC5976, the clusters run persistent and highly tailored phishing operations.

The cluster has also abused WhatsApp’s legitimate companion-device linking process.

Russian cyber espionage clusters

Targets are told they must link their account to join a secure call, chat, or document-sharing session; in reality, they authorize an attacker-controlled device.

UNC7005 initially re-used the website template from a previous “embassy invite” themed operation in late April 2026 in a different operation spoofing the legitimate GLOBSEC forum in May 2026.


 WhatsApp compromise flow (Source : GTIG).
 WhatsApp compromise flow (Source : GTIG).

GTIG further identified pages that attempt to record audio and video through a fake voice-call interface after the WhatsApp account is linked.

UNC7005’s toolkit extends beyond identity-flow abuse. In a broader May campaign, it served the VIDAR information stealer to Windows users and AtomicStealer to macOS users through a fake Ukraine-support summit application.

In August, it impersonated the Finnish Operations Center and redirected targets through legitimate Google OAuth pages toward attacker-controlled, unverified cloud projects designed to capture authentication tokens.

The group has also been connected to malicious captive-portal activity at hotels and conference venues, where victims were redirected toward fake Microsoft authentication infrastructure.

Google OAuth login before redirect to attacker-controlled cloud project (Source : GTIG).
 Google OAuth login before redirect to attacker-controlled cloud project (Source : GTIG).

Google linked that infrastructure to UNC7005 device-code, malware, and OAuth operations, complementing prior public reporting by ReliaQuest and Microsoft.

UNC5976 remains operationally separate, according to GTIG. It uses fake file-sharing domains and cloud projects to automate OAuth-token collection, and has deployed a malicious Excel add-in dubbed HEADRUSH that leads to an HTA downloader.

The group has focused heavily on military, aerospace, defense-industrial, NGO, and think-tank targets, particularly in Ukraine and Armenia.

The campaigns illustrate a growing challenge for defenders: legitimate login screens are no longer proof of safety.

Organizations should restrict app-password creation, review OAuth consent grants and connected applications, monitor device-code and device-linking events, and train high-risk staff never to share verification codes, authentication URLs, QR codes, or app passwords received during a login process.

Google also advises users to stop when browsers flag suspicious destinations and to verify the URL before authenticating.

IOCs

dosportal.appUNC6293Phishing domain
foreignrelations.usUNC6293Phishing domain
107.189.18.7 C2 for VIDAR
fewfwfwfwfwf.info C2 for AtomicStealer first payload
196.251.107.171 C2 for AtomicStealer second payload

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News