CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4808

As cited

Copy frozen at (site build).

threat intel

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Google Threat Intelligence Group tracks three distinct Russian cyber espionage clusters (UNC6293, UNC7005, and UNC5976) targeting academics, diplomats, defense officials, and think tank personnel across Europe and the United States through sophisticated phishing campaigns that abuse legitimate authentication flows. The clusters employ app password phishing, OAuth phishing, device code phishing, WhatsApp device linking attacks, and malware distribution to compromise personal accounts without triggering two-factor authentication. UNC7005 and UNC5976 have escalated tactics by incorporating browser stealers, malware-as-a-service tools, and techniques to evade automated analysis, while also exploiting hospitality sector captive portals for initial access.

Why it matters: Academics, diplomats, defense sector employees, and think tank researchers face targeted phishing campaigns that abuse legitimate platform features (app passwords, OAuth, device codes, WhatsApp linking) to bypass security controls; practitioners should educate high-risk users on recognizing social engineering lures impersonating state department and diplomatic organizations, audit linked devices and app passwords, and enforce app-specific password restrictions and advanced protection programs for at-risk personnel.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Google Threat Intelligence Group tracks three distinct Russian cyber espionage clusters (UNC6293, UNC7005, and UNC5976) targeting academics, diplomats, defense officials, and think tank personnel across Europe and the United States through sophisticated phishing campaigns that abuse legitimate authentication flows. The clusters employ app password phishing, OAuth phishing, device code phishing, WhatsApp device linking attacks, and malware distribution to compromise personal accounts without triggering two-factor authentication. UNC7005 and UNC5976 have escalated tactics by incorporating browser stealers, malware-as-a-service tools, and techniques to evade automated analysis, while also exploiting hospitality sector captive portals for initial access.

Why it matters: Academics, diplomats, defense sector employees, and think tank researchers face targeted phishing campaigns that abuse legitimate platform features (app passwords, OAuth, device codes, WhatsApp linking) to bypass security controls; practitioners should educate high-risk users on recognizing social engineering lures impersonating state department and diplomatic organizations, audit linked devices and app passwords, and enforce app-specific password restrictions and advanced protection programs for at-risk personnel.

VendorsMicrosoftAppleGoogle
Actorsapt29midnight blizzard
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary