gcp Google Cloud Blog ·

Google details Russian cyber espionage targeting using abused authentication flows

blogsecuritysecurity-advisoryengineerfinancegovernment
security announcement

Google Threat Intelligence Group (GTIG) is tracking three suspected Russian cyber espionage clusters (UNC6293, UNC7005, UNC5976) that abuse legitimate authentication flows. These persistent campaigns use sophisticated social engineering to compromise personal accounts in academia, aerospace, defense, government, and think tanks across Europe and the US. GTIG highlights these operations to help targets recognize malicious outreach, as the abuse of legitimate flows can mask phishing attempts. UNC7005 is also tied to hospitality captive portal redirects and deploys malware.

  • UNC6293: Evolving app password and OAuth phishing tactics
  • UNC7005: Device code phishing and malware deployment
Notes (2)
  • UNC6293: Evolving app password and OAuth phishing tactics

    UNC6293, assessed to be a sub-cluster of ICE RELIC (APT29), continues to impersonate the US State Department. Initially using app password phishing, where attackers convinced targets to set and share specific app passwords, the group has evolved to incorporate OAuth phishing by requesting verification codes or URLs after legitimate logins.

  • UNC7005: Device code phishing and malware deployment

    UNC7005 (aka STORM-2945), another cluster linked to ICE RELIC, targets academia, diplomatic, and nonprofit personnel with app password and device code phishing operations. This group often spoofs legitimate events like GLOBSEC and employs system fingerprinting and evasion techniques, while also incorporating malware into its campaigns.

Read the original announcement →

https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia/

Related releases