Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks with…
Intelligence analysis by Llama

Suspected Russian hackers have been observed using sophisticated social engineering tactics to compromise personal accounts across multiple platforms. They have been targeting individuals working in academia, aerospace and defense, governments, and think tanks across Europe and the U.S.
Imagine you're at a conference, and someone sends you an email inviting you to a meeting. But instead of being a real meeting, it's a trick to get you to give them your password. This is what the hackers are doing - they're sending fake emails to trick people into giving them their passwords. They're using a technique called OAuth phishing, which is like a fake login page that looks real but is actually a trick to get your password.
Analysis
Ice Relic and the UNC6293 Sub-Cluster
The Ice Relic threat group, also known as APT29 or Cozy Bear, has been observed engaging in persistent and adaptive phishing campaigns. One of its sub-clusters, UNC6293, has been found to be using a Google account feature called application specific passwords to seize control of victim accounts. This tactic was first detailed by Google and the Citizen Lab in June 2025.
Since then, the threat actor has continued to engage in phishing campaigns that tend to be small in scope, targeting fewer than five users at a time. The lures used in these campaigns revolve around diplomatic themes and upcoming conferences or meetings. For example, in December 2025, Volexity highlighted some of the lures used by the threat actor, which included invitations to diplomatic events and conferences.
In June 2026, Google observed the threat actor conducting OAuth phishing by requesting targets to share either the full URL or verification code after performing a legitimate login to an external provider. Once the requested verification code is provided, it allows the attackers to access the target's account.
UNC5976 and the OAuth Phishing Campaigns
Another threat group, UNC5976, has been found to use OAuth phishing techniques and automate the collection of tokens by abusing cloud infrastructure. The adversary is believed to be active since at least March 2026.
To perform these OAuth phishing campaigns, UNC5976 purchased domains, usually using file-sharing-related domain names, and then created a cloud project related to that domain. These domains host a fake file-sharing page. After a target visits the page for a few seconds, the page displays a pop-up login dialog.
The pop-up features a 'Continue with Google' button that, if clicked, redirects the victim to the legitimate Google OAuth login page, asking them to sign in to continue. Upon successful authentication, the victim is sent to a Google Cloud project URL that hosts malicious scripts designed to retrieve the authentication token from the URL and stage it for later use.
UNC7005 and the WhatsApp Compromise Flow
In addition, UNC5976 has been observed leveraging a rogue Excel plugin codenamed HEADRUSH that's used to deliver an HTML Application (HTA) downloaded. The malware, discovered in April 2026, is distributed via a fake domain impersonating a Ukrainian research institute. There are indications that the artifact may have been used to target a Ukrainian aerospace and imaging company, although the full scope of the infection remains unknown.
UNC7005 and the Storm-2945 Threat Actor
The threat actor that has emerged as the core focus of Google's research is UNC7005 (aka Storm-2945), which it identified in February 2026. This threat actor has been found to mainly target academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the U.S.
Both UNC6293 and UNC7005 are believed to be related to a sub-group within Ice Relic that's focused on initial access operations, while relying on commercial residential proxies for post-compromise activity. Like UNC6293, UNC7005 has conducted highly selective app password phishing operations aimed at individuals of interest to the Kremlin.
The hacking group has also engaged in device code phishing operations targeting both Microsoft and WhatsApp accounts, with the former making use of phishing emails containing invitations to diplomatic events and conferences. The messages embed a link to an attacker-controlled site, which profiles the site visitor and then prompts them to confirm their participation in the event and state their main course and wine preferences.
It's worth noting that the use of wine-related lures has been a recurring theme in Ice Relic attacks dating back to April 2023. Some aspects of the activity were codenamed SPIKEDWINE by Zscaler.
Conclusion
The suspected Russian hackers have been using sophisticated tactics to compromise personal accounts and gain access to sensitive information. The threat groups, including UNC6293, UNC5976, and UNC7005, have been observed engaging in persistent and adaptive phishing campaigns, using OAuth phishing techniques, and automating the collection of tokens by abusing cloud infrastructure.
It is essential for individuals and organizations to be aware of these tactics and take necessary precautions to protect themselves from these threats.
Key points
- Three suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe and the U.S.
- The threat groups, including UNC6293, UNC5976, and UNC7005, have been observed engaging in persistent and adaptive phishing campaigns, using OAuth phishing techniques, and automating the collection of tokens by abusing cloud infrastructure.
- The hackers are using sophisticated tactics to compromise personal accounts and gain access to sensitive information, including device code phishing operations targeting both Microsoft and WhatsApp accounts.
If the development of these threat groups is addressed positively, it could lead to increased awareness and education among individuals and organizations about the risks of OAuth phishing and other sophisticated tactics. This could result in improved security measures and a reduction in the number of successful attacks.
If the development of these threat groups is not addressed, it could lead to a significant increase in the number of successful attacks, resulting in the compromise of sensitive information and potentially even physical harm to individuals and organizations.


