Russian APTs Leverage Legitimate Authentication Flows in Sophisticated Phishing Campaigns
Google's Threat Intelligence Group (GTIG) has uncovered three distinct Russian cyber espionage clusters – UNC6293, UNC7005, and UNC5976 – employing legitimate authentication flows to target individuals in critical sectors across Europe and the U.S. These advanced persistent threats (APTs) are utilizing sophisticated social engineering tactics, including OAuth and app password phishing, to compromise personal accounts and exfiltrate sensitive information.
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S.
These clusters include **UNC6293**, **UNC7005**, and **UNC5976**.
"These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms," **Google Threat Intelligence Group (GTIG)** researchers Gabby Roncone and Wesley Shields said in a report published today.
### UNC6293: Persistent App Password Phishing
**UNC6293**, first detailed by **Google** and the **Citizen Lab** in June 2025, is assessed to be a sub-cluster of **Ice Relic** (formerly **APT29**), which is also tracked under the monikers **Cozy Bear** and **Midnight Blizzard**. The hacking crew was previously attributed to a campaign that abused a Google account feature called application-specific passwords to seize control of victim accounts.
Since then, the threat actor has continued to engage in small-scope phishing campaigns, targeting fewer than five users at a time. They impersonate State Department officials to perform app password phishing, with application names and lures revolving around diplomatic themes and upcoming conferences or meetings.
As recently as June 2026, Google observed the threat actor conducting OAuth phishing by requesting targets to share either the full URL or verification code after performing a legitimate login to an external provider. Once the requested verification code is provided, it allows the attackers to access the target's account.
### UNC5976: Cloud Infrastructure Abuse for OAuth Phishing
**UNC5976**, the second threat group with an authentication focus, has been found to use OAuth phishing techniques and automate the collection of tokens by abusing cloud infrastructure. The adversary is believed to be active since at least March 2026.
"To perform these OAuth phishing campaigns, UNC5976 purchased domains, usually using file-sharing-related domain names, and then created a cloud project related to that domain," GTIG said. "These domains host a fake file sharing page. After a target visits the page for a few seconds, the page displays a pop-up login dialog."
The pop-up features a "Continue with Google" button that, if clicked, redirects the victim to the legitimate Google OAuth login page, asking them to sign in to continue. Upon successful authentication, the victim is sent to a Google Cloud project URL that hosts malicious scripts designed to retrieve the authentication token from the URL and stage it for later use.
The threat actor is estimated to have created no less than 12 new domains and related infrastructure since March 2026, all of which have since been disrupted by Google. The actions are said to have prompted UNC5976 to pivot away from Google infrastructure to other providers to host their phishing pages.

In addition, UNC5976 has been observed leveraging a rogue Excel plugin codenamed **HEADRUSH** that's used to deliver an HTML Application (HTA) downloaded. The malware, discovered in April 2026, is distributed via a fake domain impersonating a Ukrainian research institute. There are indications that the artifact may have been used to target a Ukrainian aerospace and imaging company, although the full scope of the infection remains unknown.
"Its operational focus is primarily centered on the military, aerospace, defense industrial base, and NGOs/think tanks," Google said. "Much of the group's geographic targeting has centered on Ukraine and Armenia."
### UNC7005 Employs Myriad Tactics
The threat actor that has emerged as the core focus of GTIG's research is **UNC7005** (aka **Storm-2945**), which it identified in February 2026 and has been found to mainly target academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the U.S.
Both UNC6293 and UNC7005 are believed to be related to a sub-group within Ice Relic that's focused on initial access operations, while relying on commercial residential proxies for post-compromise activity. Like UNC6293, UNC7005 has conducted highly selective app password phishing operations aimed at individuals of interest to the Kremlin.
The hacking group has also engaged in device code phishing operations targeting both **Microsoft** and **WhatsApp** accounts. The Microsoft campaigns utilize phishing emails containing invitations to diplomatic events and conferences, embedding links to attacker-controlled sites that profile visitors and prompt them to confirm participation and preferences.
It's worth noting that the use of wine-related lures has been a recurring theme in Ice Relic attacks dating back to April 2023. Some aspects of the activity were codenamed **SPIKEDWINE** by **Zscaler**.
"In May and June 2026, UNC7005 conducted social engineering operations spoofing WhatsApp," Google said. "The phishing pages distributed by the attacker lure targets into linking their WhatsApp accounts with an attacker-controlled device in order to join a secure WhatsApp call, chat, or document share. The attacker also attempts multiple other methods of compromise after the device is linked."
Once the page is accessed, the target is asked to provide a phone number. The number is then used to create a legitimate WhatsApp device link request with the attacker device, after which it displays the legitimate QR and linking code to the target along with instructions to the user to link their device.
After the target's account is successfully linked to the attacker's WhatsApp device, the phishing page serves an additional prompt to the user to either join a voice call, encrypted chat, or download a file. If the victim ends up joining the voice call, it triggers the execution of JavaScript to record their audio and video, and send the recording to a command-and-control (C2) endpoint.
Should the encrypted chat option be chosen, the JavaScript prompts the target to copy the username and password presented to them to log in on a secondary URL. The exact nature of the file download remains unknown.
Around May 2026, UNC7005 is also said to have augmented its tradecraft with commodity infostealers like **Vidar** and **Atomic** (aka **AMOS**) to siphon data from Windows and macOS hosts. This was used to target U.S.-based academics, diplomats, and researchers focused on Russia and former Soviet states with phishing emails containing links to malicious URLs. The URL leads to a web page spoofing a summit related to a "resolution in support of Ukraine," urging them to download a summit companion application to read the full resolution.
"In early August 2026, UNC7005 began Google account OAuth phishing operations using cloud infrastructure," GTIG said. "Beginning on July 31, 2026, UNC7005 registered domains spoofing the legitimate Finnish Operations Center (FOC), which supports Finnish companies in the defense and security markets, specifically in the context of the **North Atlantic Treaty Organization (NATO)**."
"Between August 6 and August 13, 2026, UNC7005 sent targeted phishing emails linking to an attacker-controlled domain to targets in or related to the European defense industry."
Users who end up navigating to the domain are redirected to a legitimate Google OAuth login page that prompts them to sign in to their account.