- What: Google Threat Intelligence Group detailed three suspected Russian espionage clusters, UNC6293, UNC7005, and UNC5976, that phish authentication flows rather than passwords, using OAuth consent, application specific passwords, device code grants, and WhatsApp device linking.
Google Threat Intelligence Group published research on August 20, 2026 linking three suspected Russian espionage clusters to phishing campaigns that never ask for a password. UNC6293, UNC7005, and UNC5976 target academia, aerospace and defense, government, and think tank personnel across Europe, Ukraine, and the United States. All three attack the authentication flow itself: OAuth consent, application specific passwords, device code grants, and WhatsApp device linking. A completed MFA rollout stops none of it.
Three clusters, one operating model
GTIG researchers Gabby Roncone and Wesley Shields describe the activity as persistent and adaptive, focused on personal accounts across multiple platforms rather than corporate mailboxes. UNC6293 is assessed as a sub-cluster of Ice Relic, previously APT29, also tracked as Cozy Bear and Midnight Blizzard. UNC7005, also tracked by Microsoft as Storm-2945, was identified in February 2026. Both UNC6293 and UNC7005 are tied to an Ice Relic sub-group dedicated to initial access, and both use commercial residential proxies for post-compromise activity so that logins appear to come from consumer IP space. UNC5976 has been active since at least March 2026 and centers on military, aerospace, the defense industrial base, and NGOs, with geographic focus on Ukraine and Armenia.
UNC5976 built token collection on cloud infrastructure
UNC5976 automated OAuth token harvesting using legitimate cloud services. The group purchased domains with file-sharing themed names, then created a cloud project tied to each domain. The result looks like ordinary SaaS infrastructure to a proxy or a mail gateway because, at the network layer, most of it is.
- The target lands on a fake file sharing page and waits a few seconds before a login dialog pops up.
- The dialog presents a Continue with Google button.
- Clicking it redirects the victim to the real Google OAuth login page, with a valid certificate and a real Google domain in the address bar.
- After successful authentication, the victim is redirected to a Google Cloud project URL.
- Scripts hosted at that URL strip the authentication token out of the URL and stage it for the operator to use later.
Google counted no less than 12 new domains and their supporting infrastructure created since March 2026, and disrupted all of them. The response worked in the narrow sense and failed in the broad one: UNC5976 pivoted away from Google infrastructure and moved its phishing pages to other providers. UNC5976 also runs a malware line. A rogue Excel plugin codenamed HEADRUSH, discovered in April 2026, delivers an HTA downloader and was distributed from a fake domain impersonating a Ukrainian research institute. Indications point to use against a Ukrainian aerospace and imaging company, though GTIG says the full scope of that infection is not known.
In the UNC5976 flow the victim authenticates on the genuine Google login page, satisfies MFA, and sees no credential prompt on an attacker domain. The theft happens after authentication succeeds, in the redirect. User awareness training built around checking the URL bar does not catch this.
UNC7005 links your WhatsApp to their device
The most consequential technique in the report is UNC7005 spoofing WhatsApp during May and June 2026. Phishing pages told targets they needed to link their WhatsApp account to join a secure call, an encrypted chat, or a document share. The flow abuses the real device linking feature end to end.
- The page asks the target for a phone number.
- That number is used to generate a genuine WhatsApp device link request against an attacker-controlled device.
- The page displays the real QR code and linking code returned by WhatsApp, plus instructions telling the user how to complete the link.
- Once linked, the attacker device receives message traffic, and the page then pushes the target toward a voice call, an encrypted chat, or a file download.
Choosing the voice call triggers JavaScript that records the target's audio and video and ships the recording to a command-and-control endpoint. The linked device is the persistent access; the call and chat prompts are additional collection layered on top. UNC7005 also runs device code phishing against Microsoft accounts, using invitations to diplomatic events and conferences. The attacker-controlled site profiles the visitor, then asks them to confirm attendance and state their main course and wine preferences. Wine-themed lures have been an Ice Relic signature since April 2023, tracked by Zscaler as SPIKEDWINE.
UNC6293 and the app password gap
UNC6293 was first documented by Google and the Citizen Lab in June 2025 for abusing Google application specific passwords, credentials that bypass MFA by design so that legacy clients can connect. The group has kept at it, running campaigns that hit fewer than five users at a time while impersonating State Department officials, with application names and lures built around diplomatic themes and upcoming meetings. Volexity flagged some of this in December 2025. As recently as June 2026, GTIG watched UNC6293 shift to OAuth phishing, asking targets to paste back either the full redirect URL or the verification code after a legitimate login. The code is the account.
Why your controls stay quiet
Every technique here produces a valid session issued by the real identity provider. There is no credential stuffing pattern, no impossible travel when residential proxies are in play, and no malicious binary in the OAuth cases. Campaigns sized at under five recipients stay below the volume thresholds most mail security tooling uses to cluster and alert. WhatsApp device linking sits entirely outside enterprise visibility because the account is personal, which is precisely why these clusters target personal accounts belonging to people with professional access.
Anyone in academia, diplomacy, defense, or think tank work who deals with unfamiliar contacts should open WhatsApp Settings, Linked Devices, and log out anything they do not recognize. A linked device from May or June 2026 may still be reading message traffic today.
What to do this week
- Disable application specific passwords across the tenant if your Google or Microsoft policy still permits them, and audit any that exist.
- Block or restrict the device code grant flow in Entra ID Conditional Access; it has almost no legitimate use outside input-constrained devices.
- Move to admin-approved OAuth app consent so users cannot grant third-party access on their own.
- Review OAuth grants issued since March 2026, especially to apps with file-sharing or document-collaboration names.
- Brief high-risk staff that no legitimate meeting platform requires WhatsApp device linking, and that no support process asks for a URL or a verification code.
- Enroll executives, researchers, and diplomatic staff in phishing-resistant authentication and in Google Advanced Protection where personal accounts are the exposure.
- Add detection for successful authentications followed immediately by redirects to cloud project URLs, and for sign-ins sourced from residential proxy ranges.
The bottom line
Three separate clusters converged on the same conclusion: attacking authentication flows beats attacking credentials. Google removed 12 domains and the operators kept working the next day on someone else's infrastructure. Treat OAuth consent, app passwords, device codes, and messaging app device linking as privileged operations with the same scrutiny you apply to admin rights, because for these actors that is exactly what they are.
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us