NATION-STATE

Three Russian Clusters Are Phishing Auth Flows, Not Passwords

OAuth, App Passwords, and WhatsApp Device Linking. Google Threat Intelligence Group tied UNC6293, UNC7005, and UNC5976 to phishing campaigns that never ask for a password.

Matt Lucas  |  August 23, 2026  |  5 min
Editorial hero illustration
CVE in this postCVE-2026-19478Live detections →All RedEye CVEs →
3
suspected Russian clusters
12+
attacker domains disrupted
<5
targets per phishing wave
Aug 20, 2026
GTIG report date
Detected by CaverLive detection for CVE-2026-19478 in the RedEye Intel Feed →
TL;DR
  • What: Google Threat Intelligence Group detailed three suspected Russian espionage clusters, UNC6293, UNC7005, and UNC5976, that phish authentication flows rather than passwords, using OAuth consent, application specific passwords, device code grants, and WhatsApp device linking.

Google Threat Intelligence Group published research on August 20, 2026 linking three suspected Russian espionage clusters to phishing campaigns that never ask for a password. UNC6293, UNC7005, and UNC5976 target academia, aerospace and defense, government, and think tank personnel across Europe, Ukraine, and the United States. All three attack the authentication flow itself: OAuth consent, application specific passwords, device code grants, and WhatsApp device linking. A completed MFA rollout stops none of it.

Three clusters, one operating model

GTIG researchers Gabby Roncone and Wesley Shields describe the activity as persistent and adaptive, focused on personal accounts across multiple platforms rather than corporate mailboxes. UNC6293 is assessed as a sub-cluster of Ice Relic, previously APT29, also tracked as Cozy Bear and Midnight Blizzard. UNC7005, also tracked by Microsoft as Storm-2945, was identified in February 2026. Both UNC6293 and UNC7005 are tied to an Ice Relic sub-group dedicated to initial access, and both use commercial residential proxies for post-compromise activity so that logins appear to come from consumer IP space. UNC5976 has been active since at least March 2026 and centers on military, aerospace, the defense industrial base, and NGOs, with geographic focus on Ukraine and Armenia.

UNC5976 built token collection on cloud infrastructure

UNC5976 automated OAuth token harvesting using legitimate cloud services. The group purchased domains with file-sharing themed names, then created a cloud project tied to each domain. The result looks like ordinary SaaS infrastructure to a proxy or a mail gateway because, at the network layer, most of it is.

Google counted no less than 12 new domains and their supporting infrastructure created since March 2026, and disrupted all of them. The response worked in the narrow sense and failed in the broad one: UNC5976 pivoted away from Google infrastructure and moved its phishing pages to other providers. UNC5976 also runs a malware line. A rogue Excel plugin codenamed HEADRUSH, discovered in April 2026, delivers an HTA downloader and was distributed from a fake domain impersonating a Ukrainian research institute. Indications point to use against a Ukrainian aerospace and imaging company, though GTIG says the full scope of that infection is not known.

The user does everything right and still loses

In the UNC5976 flow the victim authenticates on the genuine Google login page, satisfies MFA, and sees no credential prompt on an attacker domain. The theft happens after authentication succeeds, in the redirect. User awareness training built around checking the URL bar does not catch this.

UNC7005 links your WhatsApp to their device

The most consequential technique in the report is UNC7005 spoofing WhatsApp during May and June 2026. Phishing pages told targets they needed to link their WhatsApp account to join a secure call, an encrypted chat, or a document share. The flow abuses the real device linking feature end to end.

Choosing the voice call triggers JavaScript that records the target's audio and video and ships the recording to a command-and-control endpoint. The linked device is the persistent access; the call and chat prompts are additional collection layered on top. UNC7005 also runs device code phishing against Microsoft accounts, using invitations to diplomatic events and conferences. The attacker-controlled site profiles the visitor, then asks them to confirm attendance and state their main course and wine preferences. Wine-themed lures have been an Ice Relic signature since April 2023, tracked by Zscaler as SPIKEDWINE.

UNC6293 and the app password gap

UNC6293 was first documented by Google and the Citizen Lab in June 2025 for abusing Google application specific passwords, credentials that bypass MFA by design so that legacy clients can connect. The group has kept at it, running campaigns that hit fewer than five users at a time while impersonating State Department officials, with application names and lures built around diplomatic themes and upcoming meetings. Volexity flagged some of this in December 2025. As recently as June 2026, GTIG watched UNC6293 shift to OAuth phishing, asking targets to paste back either the full redirect URL or the verification code after a legitimate login. The code is the account.

Why your controls stay quiet

Every technique here produces a valid session issued by the real identity provider. There is no credential stuffing pattern, no impossible travel when residential proxies are in play, and no malicious binary in the OAuth cases. Campaigns sized at under five recipients stay below the volume thresholds most mail security tooling uses to cluster and alert. WhatsApp device linking sits entirely outside enterprise visibility because the account is personal, which is precisely why these clusters target personal accounts belonging to people with professional access.

Check linked devices now

Anyone in academia, diplomacy, defense, or think tank work who deals with unfamiliar contacts should open WhatsApp Settings, Linked Devices, and log out anything they do not recognize. A linked device from May or June 2026 may still be reading message traffic today.

What to do this week

The bottom line

Three separate clusters converged on the same conclusion: attacking authentication flows beats attacking credentials. Google removed 12 domains and the operators kept working the next day on someone else's infrastructure. Treat OAuth consent, app passwords, device codes, and messaging app device linking as privileged operations with the same scrutiny you apply to admin rights, because for these actors that is exactly what they are.

Questions about your exposure?

RedEye Security provides assessments for organizations that need to understand their real risk.

Talk to us