Security News Russian-linked hackers turn Google and WhatsApp logins into phishing traps

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,068
5,865
2,168
Germany
Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features to compromise personal accounts of people in sensitive sectors across Europe and the US, Google says.

Key takeaways
Google is tracking UNC6293, UNC7005 and UNC5976, which it assesses with high confidence to have a Russian nexus
The campaigns abuse legitimate Google OAuth, app-password and device-linking workflows rather than software vulnerabilities
UNC7005 has also used WhatsApp device linking to attach attacker-controlled devices to victims’ accounts
Targets include academics, diplomats, defense personnel, government-linked users and think-tank researchers
Legitimate sign-in pages become phishing traps
The Google Threat Intelligence Group (GTIG) says victims may encounter genuine authentication pages during these attacks. UNC6293 has asked targets to complete legitimate logins and surrender verification codes or URLs, while UNC5976 built fake file-sharing pages that redirected users through authentic Google OAuth screens.

After authentication, victims could be sent to attacker-controlled cloud projects designed to capture access tokens. Google says it disrupted at least 12 domains and related infrastructure created by UNC5976, which has since started shifting parts of its phishing infrastructure away from Google services.

WhatsApp linking gives attackers another route in
UNC7005, also tracked by Microsoft as Storm-2945, used fake invitations and secure-communication lures to target academics, diplomats and nonprofit personnel. In May and June, phishing pages impersonating WhatsApp asked victims to enter a phone number and approve a legitimate device-link request for an attacker-controlled device.

Once linked, the attacker could gain ongoing account access. Google also observed prompts for fake encrypted chats, file downloads and voice calls. One call flow used malicious JavaScript to record a target’s audio and video. In August, the same cluster used Google OAuth phishing against people connected to Europe’s defense industry.

Why this matters beyond high-profile targets
These operations are highly selective, but the techniques matter to everyone because they rely on familiar, legitimate-looking security workflows. A real Google sign-in page, QR code or WhatsApp linking prompt is not proof that the request leading to it is trustworthy.

Users should verify unexpected invitations through a separate channel, never share app passwords or verification codes, review linked WhatsApp devices, and treat unverified OAuth consent screens as a warning sign. Google also recommends that high-risk users consider its Advanced Protection Program.

Stay safer from phishing and account-takeover lures
Attackers increasingly build scams around legitimate services, so the initial message or link deserves as much scrutiny as the login page itself. Bitdefender Scamio can analyze suspicious messages, links and QR codes before you interact with them, while Bitdefender Ultimate Security adds anti-phishing, web, email and scam protection across supported devices.
 
The main lesson: legitimate authentication does not make the original request legitimate.

These campaigns appear to rely primarily on social engineering and consent abuse rather than exploiting a vulnerability in Google or WhatsApp. A victim may be directed to a genuine Google login page, a real OAuth flow, or an authentic WhatsApp device-linking screen, while the surrounding request is controlled by the attacker.

Important defensive points:

  • Never provide a verification code, app password, recovery code, or OAuth authorization to someone who requested it through email, chat, or a phone call.
  • Do not approve an unexpected WhatsApp device-linking request. Review WhatsApp’s Linked devices section and remove anything unfamiliar.
  • Check the Google Account Security page for recent activity, active sessions, third-party access, passkeys, security keys, and app passwords.
  • Revoke unknown OAuth applications and app passwords. Revoking access is safer than merely changing the password if an access token or application credential may already have been obtained.
  • Use a password manager or passkey where possible. Unexpected sign-in prompts that do not correspond to an action you initiated should be denied.
  • Verify invitations, urgent requests, and file-sharing links through a separate, trusted communication channel.
  • For high-risk users, consider hardware security keys and Google’s Advanced Protection Program.

If an account may already be compromised, change the password from a trusted device, revoke active sessions and third-party access, remove unknown linked devices, review forwarding rules and recovery settings, and notify the relevant organization’s security team. Also preserve the original messages, URLs, timestamps, and headers for investigation.

The article’s broader warning is sound: a real sign-in page or QR code confirms only that the authentication service is genuine; it does not confirm that the person or website directing you there is trustworthy.