Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features to compromise personal accounts of people in sensitive sectors across Europe and the US, Google says.
Key takeaways
Google is tracking UNC6293, UNC7005 and UNC5976, which it assesses with high confidence to have a Russian nexus
The campaigns abuse legitimate Google OAuth, app-password and device-linking workflows rather than software vulnerabilities
UNC7005 has also used WhatsApp device linking to attach attacker-controlled devices to victims’ accounts
Targets include academics, diplomats, defense personnel, government-linked users and think-tank researchers
Legitimate sign-in pages become phishing traps
The Google Threat Intelligence Group (GTIG) says victims may encounter genuine authentication pages during these attacks. UNC6293 has asked targets to complete legitimate logins and surrender verification codes or URLs, while UNC5976 built fake file-sharing pages that redirected users through authentic Google OAuth screens.
After authentication, victims could be sent to attacker-controlled cloud projects designed to capture access tokens. Google says it disrupted at least 12 domains and related infrastructure created by UNC5976, which has since started shifting parts of its phishing infrastructure away from Google services.
WhatsApp linking gives attackers another route in
UNC7005, also tracked by Microsoft as Storm-2945, used fake invitations and secure-communication lures to target academics, diplomats and nonprofit personnel. In May and June, phishing pages impersonating WhatsApp asked victims to enter a phone number and approve a legitimate device-link request for an attacker-controlled device.
Once linked, the attacker could gain ongoing account access. Google also observed prompts for fake encrypted chats, file downloads and voice calls. One call flow used malicious JavaScript to record a target’s audio and video. In August, the same cluster used Google OAuth phishing against people connected to Europe’s defense industry.
Why this matters beyond high-profile targets
These operations are highly selective, but the techniques matter to everyone because they rely on familiar, legitimate-looking security workflows. A real Google sign-in page, QR code or WhatsApp linking prompt is not proof that the request leading to it is trustworthy.
Users should verify unexpected invitations through a separate channel, never share app passwords or verification codes, review linked WhatsApp devices, and treat unverified OAuth consent screens as a warning sign. Google also recommends that high-risk users consider its Advanced Protection Program.
Stay safer from phishing and account-takeover lures
Attackers increasingly build scams around legitimate services, so the initial message or link deserves as much scrutiny as the login page itself. Bitdefender Scamio can analyze suspicious messages, links and QR codes before you interact with them, while Bitdefender Ultimate Security adds anti-phishing, web, email and scam protection across supported devices.