Three suspected Russian cyber espionage clusters abusing legitimate authentication mechanisms to hijack accounts belonging to academics, diplomats, defense personnel, government staff, and think-tank researchers across Europe and the United States.
Rather than relying solely on credential-harvesting pages, the operators manipulate users into completing genuine app-password, OAuth, device-code, and device-linking workflows that can hand attackers authenticated access despite multi-factor authentication protections.
GTIG assesses with high confidence that the activity has a Russian nexus, while UNC6293 and UNC7005 are assessed with moderate confidence to be initial-access subclusters associated with ICE RELIC, Google’s designation for the actor widely known as APT29.
UNC6293, first publicly detailed in June 2025, has repeatedly impersonated U.S. State Department officials to target prominent individuals critical of Russia.
Its core technique is app-password phishing: victims are instructed to generate an application-specific password often under a deceptive name such as “ms.state.gov” then provide that password to the attacker.
App passwords are designed for legacy applications that cannot support 2FA, meaning a stolen code can enable mailbox access without triggering the victim’s second authentication factor.cloud.
The group has since expanded into OAuth phishing. In June 2026, GTIG observed UNC6293 asking targets to complete a legitimate third-party login and submit the resulting full URL or “verification code” to a phishing site.
Supplying the value effectively grants the adversary authorization to access the victim’s account, turning a real authentication journey into the compromise mechanism.
UNC7005, also known as STORM-2945, has operated since at least February 2026 and targets academic, diplomatic, nonprofit, and defense-related personnel in Ukraine, Western Europe, and the U.S.
Its campaigns have used spoofed conference and embassy invitations to drive victims through Microsoft device-code authentication, where a legitimate Microsoft workflow is repurposed to bind the victim’s account to attacker-controlled access.
GTIG said the group fingerprints visitors and deploys anti-analysis checks on lure sites, indicating active efforts to filter security researchers and automated scanners.

GTIG Researchers tracked, UNC6293, UNC7005, and UNC5976, the clusters run persistent and highly tailored phishing operations.
The cluster has also abused WhatsApp’s legitimate companion-device linking process.
Russian cyber espionage clusters
Targets are told they must link their account to join a secure call, chat, or document-sharing session; in reality, they authorize an attacker-controlled device.
UNC7005 initially re-used the website template from a previous “embassy invite” themed operation in late April 2026 in a different operation spoofing the legitimate GLOBSEC forum in May 2026.

GTIG further identified pages that attempt to record audio and video through a fake voice-call interface after the WhatsApp account is linked.
UNC7005’s toolkit extends beyond identity-flow abuse. In a broader May campaign, it served the VIDAR information stealer to Windows users and AtomicStealer to macOS users through a fake Ukraine-support summit application.
In August, it impersonated the Finnish Operations Center and redirected targets through legitimate Google OAuth pages toward attacker-controlled, unverified cloud projects designed to capture authentication tokens.
The group has also been connected to malicious captive-portal activity at hotels and conference venues, where victims were redirected toward fake Microsoft authentication infrastructure.

Google linked that infrastructure to UNC7005 device-code, malware, and OAuth operations, complementing prior public reporting by ReliaQuest and Microsoft.
UNC5976 remains operationally separate, according to GTIG. It uses fake file-sharing domains and cloud projects to automate OAuth-token collection, and has deployed a malicious Excel add-in dubbed HEADRUSH that leads to an HTA downloader.
The group has focused heavily on military, aerospace, defense-industrial, NGO, and think-tank targets, particularly in Ukraine and Armenia.
The campaigns illustrate a growing challenge for defenders: legitimate login screens are no longer proof of safety.
Organizations should restrict app-password creation, review OAuth consent grants and connected applications, monitor device-code and device-linking events, and train high-risk staff never to share verification codes, authentication URLs, QR codes, or app passwords received during a login process.
Google also advises users to stop when browsers flag suspicious destinations and to verify the URL before authenticating.
IOCs
dosportal.app | UNC6293 | Phishing domain |
foreignrelations.us | UNC6293 | Phishing domain |
107.189.18.7 | C2 for VIDAR | |
fewfwfwfwfwf.info | C2 for AtomicStealer first payload | |
196.251.107.171 | C2 for AtomicStealer second payload |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide





