OAuth Exploitation
Russian threat actors are shifting away from plain old password theft and moving toward legitimate platform features like OAuth permissions. Groups like UNC6293 and UNC7005 take their time building rapport with targets, often posing as conference planners or fellow researchers over several weeks. Once trust is established, they steer targets in government, defense, and academia through standard OAuth authorization flows. By persuading victims to provide verification codes or complete legitimate OAuth authentication flows, the attackers can obtain authentication material that may allow them to access the victim’s account without needing the victim’s password.
WhatsApp Device Pairing
This strategy bleeds over into messaging platforms, where adversaries abuse WhatsApp device-pairing features to get inside personal chats. Threat actors set up fake landing pages that look like secure meeting invites or document shares. When a target visits the site, the platform triggers a genuine device-linking request and shows a valid QR or numeric code. The moment the user scans or approves it, an attacker-controlled device links to their account. From there, operators can passively monitor messages, steal confidential files, and use the compromised identity to message other targets.
Author Notes
Roncone, G., & Shields, W. (2026, August 20). Distinct Clusters Target Individuals of Interest to Russia. Google Cloud Blog. https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia
About the Author
Carmen Estela is a Cybersecurity Research Analyst at Cyber Defense Magazine and a Women in Cybersecurity Award Candidate. She recently graduated with a Master of Science degree from the University of Central Florida and holds a Bachelor’s degree in Criminology from the University of Florida with certifications in Data Analytics and AI Fundamentals. She frequently speaks and volunteers at well-known industry gatherings, such as BSides Orlando and BSides Jax, where she offers her perspectives on emerging cyber trends. Carmen is committed to advancing the standards of governance, risk, and compliance within cybersecurity. She has also served as an adult protective investigator, police dispatcher, and legal intern, applying investigative skills across law enforcement, academic, and public service settings.
Reach her online at [email protected].

