CyberSecurityNews

Russian Hackers Abuse OAuth and WhatsApp Device Linking to Hijack High-Value Accounts


Suspected Russian cyber-espionage groups are increasingly turning ordinary sign-in and device-linking features into tools for account takeover.

Their latest campaigns do not depend on breaking passwords or exploiting a software flaw. Instead, they persuade targets to approve actions that appear legitimate.

The activity has targeted people in academia, aerospace, defense, government, nonprofit organizations, and think tanks across Europe and the United States.

Attackers use tailored conference invitations, diplomatic themes, file-sharing offers, and messages that create pressure to authenticate quickly.

Analysts at Google Cloud identified three distinct clusters, tracked as UNC6293, UNC7005, and UNC5976, using phishing, OAuth abuse, app-password theft, device-code lures, and malware.

UNC6293 requesting ‘verification code’ on a phishing page (Source – Google Cloud)

Google assesses with high confidence that the clusters have a Russian nexus, based on targeting patterns, phishing themes, and operational methods.

Google Cloud said in a report shared with Cyber Security News (CSN) that the operations are troubling because the victim often interacts with a real authentication page or a genuine account feature.

That makes the scam look safer than a traditional fake login page and creates a blind spot for organizations that mainly monitor corporate accounts.

Recent Russian device-code phishing activity has already shown how attackers can misuse legitimate sign-in workflows to capture access tokens.

Russian Hackers Abuse OAuth and WhatsApp Device Linking

UNC7005, also known as STORM-2945, has used carefully selected phishing operations against individuals of interest to the Russian state.

Its lures commonly impersonate events, embassies, conferences, or trusted organizations, encouraging recipients to register, access documents, or join a secure conversation.

In one WhatsApp-focused campaign seen during May and June 2026, victims were directed to a fake page and asked to enter their phone number.

The page then generated a legitimate WhatsApp device-linking request for an attacker-controlled device and displayed the real QR code or linking code to the target.

Social engineering landing page (Source – Google Cloud)

If the target approved the request in WhatsApp, the attacker gained a linked session capable of accessing the victim’s messages.

This mirrors the wider risk documented in WhatsApp GhostPairing account hijacks, where social engineering turns a normal companion-device feature into unauthorized account access.

After device linking, UNC7005’s pages could present a fake voice call, encrypted chat, or file-transfer option.

The false call page used malicious browser code to record audio and video, while the chat path displayed credentials for a secondary login page. Google Cloud could not determine what file was staged in the file-transfer scenario.

The same cluster also abused OAuth flows against Google and Microsoft accounts. In August 2026, it used domains impersonating the Finnish Operations Center to target people connected to Europe’s defense sector.

Victims who selected “Sign in With Google” were taken to a real login page before being redirected to an attacker-controlled, unverified cloud project designed to collect authentication tokens.

That tactic differs from password theft because a victim can enter correct credentials only on a legitimate provider page and still give an attacker access.

Earlier reporting on Google services phishing abuse illustrates how trusted infrastructure can make malicious requests appear unusually convincing.

Malware, Defense, and Impact

UNC7005 also expanded beyond authentication abuse. In a broader campaign in late May 2026, attackers used a fake Ukraine-related summit site to distribute browser-information stealers to Windows and macOS users.

Windows visitors received VIDAR, while macOS users received ATOMIC, two malware families built to collect saved browser data such as credentials, cookies, addresses, and payment details.

These actors abuse legitimate features and infrastructure to make malicious activity harder to distinguish from normal account use. The affected accounts are often personal accounts, which may fall outside an employer’s normal monitoring coverage.

For defenders, the message is simple: a familiar-looking invitation, a valid QR code, or a genuine sign-in page does not prove the request is safe.

WhatsApp compromise flow (Source – Google Cloud)

Similar Teams meeting invite attacks have demonstrated how valid device-code workflows can be weaponized to obtain durable access tokens without stealing passwords.

Users should inspect browser URLs before signing in, avoid proceeding past warnings for suspicious websites, and independently verify invitations through contact details obtained outside the message.

They should never share app passwords, verification codes, or a full authentication URL with another person.

Organizations should routinely review linked devices on both personal and work messaging accounts, enforce two-factor authentication and registration locks where available, and validate contacts through a separate channel.

High-risk users should remove unfamiliar linked devices immediately and treat unexpected requests to join “secure” chats or calls as potential phishing attempts.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Domainatribudosportal.appUNC6293 network indicator
Domainforeignrelations.usUNC6293 phishing infrastructure
IP address107.189.18.7VIDAR command-and-control server
Domainfewfwfwfwfwf.infoUNC6293 network indicator
IP address196.251.107.171UNC6293 network indicator
Domainmiov2iaiaoubqosiqoiajwowiwjso.onlineUNC6293 network indicator
Domainmioisiskwowiwjowuwjwolab.clubUNC6293 network indicator
Domainchamber-ua.orgUNC7005 network indicator
Domainwa-connect.euUNC7005 WhatsApp-themed infrastructure
Domainwa-connect.netUNC7005 WhatsApp-themed infrastructure
Domainwa-invite.comUNC7005 WhatsApp-themed infrastructure
Domainwa-device.comUNC7005 WhatsApp-themed infrastructure
Domainwa-meeting.comUNC7005 WhatsApp-themed infrastructure
Domainshopinvite.orgUNC7005 network indicator
Domainmy-invite.orgUNC7005 device-code phishing infrastructure
Domainglobsec.netUNC7005 network indicator
Domainstatistic-ms.liveUNC7005 ENGINELIGHT command-and-control domain
Domainowa-ms365.comUNC7005 Microsoft OWA-themed infrastructure
Domainm365-owa.comUNC7005 Microsoft OWA-themed infrastructure
Domainms365-device.comUNC7005 Microsoft-themed infrastructure
Domainms365-live.comUNC7005 Microsoft-themed infrastructure
IP address31.57.243.154UNC7005 network indicator
IP address38.146.28.75UNC7005 network indicator
IP address104.194.159.150UNC7005 infrastructure IP address
Domainfinishoperations.comUNC7005 Finnish Operations Center spoofing domain
Domainfinishoperations.orgUNC7005 Finnish Operations Center spoofing domain
Domainfoc-share.comUNC7005 OAuth phishing infrastructure
Domainshare-foc.comUNC7005 OAuth phishing infrastructure
Domaininternal-share.comUNC7005 OAuth phishing infrastructure
Domainfoc-share.orgUNC7005 OAuth phishing infrastructure
Domaindrive.google.verify-drive.comUNC5976 OAuth phishing infrastructure
Domainmail.kiis.co.ukUNC5976 network indicator
SHA-2565b8d50c2e8cc3038b7c6e6dbf1219f6e814930a1e3c005a06a8fd1b6fa1924UNC7005 file indicator
SHA-256199a4540cf16d089217ce8f78c6177UNC7005 file indicator
SHA-2561d9299799a7b8da67c44ebec064d64542c27645f8e84de4a22ca3f6cbc843e3cVIDAR sample
SHA-256c5826032207d623a7f6caec8465af7364eccc355f9a488125752ad7c20d715920ATOMIC sample
SHA-256a3b2fb0fdde660f07b3f2b05366403b624e35777cbc07dbe66398b21bba70396UNC7005 file indicator
SHA-256a20b859c828f622028e690c943f7fa9aca426c07cab52b5aaba757ebe99857449UNC7005 file indicator
SHA-256d2856dd5a84e21c8a3d5e0e01456adb440621e3ee845fde739fcd3ca9ce62c7fUNC7005 file indicator
SHA-256142a7c501d11db4c4f6f7090895c1c3dee30de6b3f098ca3a788dc198646e529UNC7005 file indicator
SHA-25620e20b074967ed6f6e04d609ccec5ff7492665ef25f894ca3be5885afb3eb3bbUNC7005 file indicator
SHA-25619341e2653212200c568f3f900e02c7f4165967d6f7737b3fef87959846920b57HEADRUSH sample
SHA-256a5368b531ad1427c7214d4c41a2UNC5976 file indicator

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link