Google details Russian cyber espionage targeting using abused authentication flows
Google Threat Intelligence Group (GTIG) is tracking three suspected Russian cyber espionage clusters (UNC6293, UNC7005, UNC5976) that abuse legitimate authentication flows. These persistent campaigns use sophisticated social engineering to compromise personal accounts in academia, aerospace, defense, government, and think tanks across Europe and the US. GTIG highlights these operations to help targets recognize malicious outreach, as the abuse of legitimate flows can mask phishing attempts. UNC7005 is also tied to hospitality captive portal redirects and deploys malware.
- →UNC6293: Evolving app password and OAuth phishing tactics
- →UNC7005: Device code phishing and malware deployment
Notes (2) ›
- UNC6293: Evolving app password and OAuth phishing tactics
UNC6293, assessed to be a sub-cluster of ICE RELIC (APT29), continues to impersonate the US State Department. Initially using app password phishing, where attackers convinced targets to set and share specific app passwords, the group has evolved to incorporate OAuth phishing by requesting verification codes or URLs after legitimate logins.
- UNC7005: Device code phishing and malware deployment
UNC7005 (aka STORM-2945), another cluster linked to ICE RELIC, targets academia, diplomatic, and nonprofit personnel with app password and device code phishing operations. This group often spoofs legitimate events like GLOBSEC and employs system fingerprinting and evasion techniques, while also incorporating malware into its campaigns.
https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia/
Related releases
- Bringing gVisor Sandboxes to Distributed Ray Clusters on Google Cloud Google Cloud Blog ·
- Introducing Gemini Enterprise for Financial Services Google Cloud Blog ·
- Google Cloud Introduces Gemini Enterprise for Legal AI Solution Google Cloud Blog ·
- Anthos Config Management gets security updates and monitoring controls Google Cloud release notes ·
- Google SecOps SIEM Adds Unroll Processor for Data Processing Pipelines Google Cloud release notes ·
- Container Optimized OS Updates Address Linux Kernel Vulnerabilities and Package Upgrades Google Cloud release notes ·