Google says three suspected Russian espionage groups have been running small, targeted phishing campaigns against people in government, defense, aerospace, academia, think tanks, and nonprofits in Europe and the United States. Google tracks the groups as UNC6293, UNC7005, and UNC5976, and says they abuse legitimate OAuth and device-code sign-in flows to gain long-term access to email and messaging accounts; UNC6293 continued using fake U.S. State Department meeting lures, while UNC7005 also used malware and Microsoft and WhatsApp account phishing.
Why it matters: These attacks are aimed at people whose personal or work accounts can expose sensitive government, policy, and research information. Organizations in the affected sectors should warn staff now about fake meeting invites and requests for verification codes, restrict risky OAuth consent flows where possible, and review account and token security.
2026.08.21
100% relevant
This article establishes a broader, multi-cluster Google-tracked Russian espionage phishing story centered on OAuth abuse and targeted social engineering, beyond the already tracked captive-portal malware campaign.
← Back to all stories