Suspected Russian cyber-espionage groups are increasingly turning ordinary sign-in and device-linking features into tools for account takeover.
Their latest campaigns do not depend on breaking passwords or exploiting a software flaw. Instead, they persuade targets to approve actions that appear legitimate.
The activity has targeted people in academia, aerospace, defense, government, nonprofit organizations, and think tanks across Europe and the United States.
Attackers use tailored conference invitations, diplomatic themes, file-sharing offers, and messages that create pressure to authenticate quickly.
Analysts at Google Cloud identified three distinct clusters, tracked as UNC6293, UNC7005, and UNC5976, using phishing, OAuth abuse, app-password theft, device-code lures, and malware.
Google assesses with high confidence that the clusters have a Russian nexus, based on targeting patterns, phishing themes, and operational methods.
Google Cloud said in a report shared with Cyber Security News (CSN) that the operations are troubling because the victim often interacts with a real authentication page or a genuine account feature.
That makes the scam look safer than a traditional fake login page and creates a blind spot for organizations that mainly monitor corporate accounts.
Recent Russian device-code phishing activity has already shown how attackers can misuse legitimate sign-in workflows to capture access tokens.
Russian Hackers Abuse OAuth and WhatsApp Device Linking
UNC7005, also known as STORM-2945, has used carefully selected phishing operations against individuals of interest to the Russian state.
Its lures commonly impersonate events, embassies, conferences, or trusted organizations, encouraging recipients to register, access documents, or join a secure conversation.
In one WhatsApp-focused campaign seen during May and June 2026, victims were directed to a fake page and asked to enter their phone number.
The page then generated a legitimate WhatsApp device-linking request for an attacker-controlled device and displayed the real QR code or linking code to the target.
.webp)
If the target approved the request in WhatsApp, the attacker gained a linked session capable of accessing the victim’s messages.
This mirrors the wider risk documented in WhatsApp GhostPairing account hijacks, where social engineering turns a normal companion-device feature into unauthorized account access.
After device linking, UNC7005’s pages could present a fake voice call, encrypted chat, or file-transfer option.
The false call page used malicious browser code to record audio and video, while the chat path displayed credentials for a secondary login page. Google Cloud could not determine what file was staged in the file-transfer scenario.
The same cluster also abused OAuth flows against Google and Microsoft accounts. In August 2026, it used domains impersonating the Finnish Operations Center to target people connected to Europe’s defense sector.
Victims who selected “Sign in With Google” were taken to a real login page before being redirected to an attacker-controlled, unverified cloud project designed to collect authentication tokens.
That tactic differs from password theft because a victim can enter correct credentials only on a legitimate provider page and still give an attacker access.
Earlier reporting on Google services phishing abuse illustrates how trusted infrastructure can make malicious requests appear unusually convincing.
Malware, Defense, and Impact
UNC7005 also expanded beyond authentication abuse. In a broader campaign in late May 2026, attackers used a fake Ukraine-related summit site to distribute browser-information stealers to Windows and macOS users.
Windows visitors received VIDAR, while macOS users received ATOMIC, two malware families built to collect saved browser data such as credentials, cookies, addresses, and payment details.
These actors abuse legitimate features and infrastructure to make malicious activity harder to distinguish from normal account use. The affected accounts are often personal accounts, which may fall outside an employer’s normal monitoring coverage.
For defenders, the message is simple: a familiar-looking invitation, a valid QR code, or a genuine sign-in page does not prove the request is safe.
.webp)
Similar Teams meeting invite attacks have demonstrated how valid device-code workflows can be weaponized to obtain durable access tokens without stealing passwords.
Users should inspect browser URLs before signing in, avoid proceeding past warnings for suspicious websites, and independently verify invitations through contact details obtained outside the message.
They should never share app passwords, verification codes, or a full authentication URL with another person.
Organizations should routinely review linked devices on both personal and work messaging accounts, enforce two-factor authentication and registration locks where available, and validate contacts through a separate channel.
High-risk users should remove unfamiliar linked devices immediately and treat unexpected requests to join “secure” chats or calls as potential phishing attempts.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | atribudosportal.app | UNC6293 network indicator |
| Domain | foreignrelations.us | UNC6293 phishing infrastructure |
| IP address | 107.189.18.7 | VIDAR command-and-control server |
| Domain | fewfwfwfwfwf.info | UNC6293 network indicator |
| IP address | 196.251.107.171 | UNC6293 network indicator |
| Domain | miov2iaiaoubqosiqoiajwowiwjso.online | UNC6293 network indicator |
| Domain | mioisiskwowiwjowuwjwolab.club | UNC6293 network indicator |
| Domain | chamber-ua.org | UNC7005 network indicator |
| Domain | wa-connect.eu | UNC7005 WhatsApp-themed infrastructure |
| Domain | wa-connect.net | UNC7005 WhatsApp-themed infrastructure |
| Domain | wa-invite.com | UNC7005 WhatsApp-themed infrastructure |
| Domain | wa-device.com | UNC7005 WhatsApp-themed infrastructure |
| Domain | wa-meeting.com | UNC7005 WhatsApp-themed infrastructure |
| Domain | shopinvite.org | UNC7005 network indicator |
| Domain | my-invite.org | UNC7005 device-code phishing infrastructure |
| Domain | globsec.net | UNC7005 network indicator |
| Domain | statistic-ms.live | UNC7005 ENGINELIGHT command-and-control domain |
| Domain | owa-ms365.com | UNC7005 Microsoft OWA-themed infrastructure |
| Domain | m365-owa.com | UNC7005 Microsoft OWA-themed infrastructure |
| Domain | ms365-device.com | UNC7005 Microsoft-themed infrastructure |
| Domain | ms365-live.com | UNC7005 Microsoft-themed infrastructure |
| IP address | 31.57.243.154 | UNC7005 network indicator |
| IP address | 38.146.28.75 | UNC7005 network indicator |
| IP address | 104.194.159.150 | UNC7005 infrastructure IP address |
| Domain | finishoperations.com | UNC7005 Finnish Operations Center spoofing domain |
| Domain | finishoperations.org | UNC7005 Finnish Operations Center spoofing domain |
| Domain | foc-share.com | UNC7005 OAuth phishing infrastructure |
| Domain | share-foc.com | UNC7005 OAuth phishing infrastructure |
| Domain | internal-share.com | UNC7005 OAuth phishing infrastructure |
| Domain | foc-share.org | UNC7005 OAuth phishing infrastructure |
| Domain | drive.google.verify-drive.com | UNC5976 OAuth phishing infrastructure |
| Domain | mail.kiis.co.uk | UNC5976 network indicator |
| SHA-256 | 5b8d50c2e8cc3038b7c6e6dbf1219f6e814930a1e3c005a06a8fd1b6fa1924 | UNC7005 file indicator |
| SHA-256 | 199a4540cf16d089217ce8f78c6177 | UNC7005 file indicator |
| SHA-256 | 1d9299799a7b8da67c44ebec064d64542c27645f8e84de4a22ca3f6cbc843e3c | VIDAR sample |
| SHA-256 | c5826032207d623a7f6caec8465af7364eccc355f9a488125752ad7c20d715920 | ATOMIC sample |
| SHA-256 | a3b2fb0fdde660f07b3f2b05366403b624e35777cbc07dbe66398b21bba70396 | UNC7005 file indicator |
| SHA-256 | a20b859c828f622028e690c943f7fa9aca426c07cab52b5aaba757ebe99857449 | UNC7005 file indicator |
| SHA-256 | d2856dd5a84e21c8a3d5e0e01456adb440621e3ee845fde739fcd3ca9ce62c7f | UNC7005 file indicator |
| SHA-256 | 142a7c501d11db4c4f6f7090895c1c3dee30de6b3f098ca3a788dc198646e529 | UNC7005 file indicator |
| SHA-256 | 20e20b074967ed6f6e04d609ccec5ff7492665ef25f894ca3be5885afb3eb3bb | UNC7005 file indicator |
| SHA-256 | 19341e2653212200c568f3f900e02c7f4165967d6f7737b3fef87959846920b57 | HEADRUSH sample |
| SHA-256 | a5368b531ad1427c7214d4c41a2 | UNC5976 file indicator |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

