As cited
Copy frozen at (site build).
threat intel
Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia
Google Threat Intelligence Group tracks three distinct Russian cyber espionage clusters (UNC6293, UNC7005, and UNC5976) targeting academics, diplomats, defense officials, and think tank personnel across Europe and the United States through sophisticated phishing campaigns that abuse legitimate authentication flows. The clusters employ app password phishing, OAuth phishing, device code phishing, WhatsApp device linking attacks, and malware distribution to compromise personal accounts without triggering two-factor authentication. UNC7005 and UNC5976 have escalated tactics by incorporating browser stealers, malware-as-a-service tools, and techniques to evade automated analysis, while also exploiting hospitality sector captive portals for initial access.
Why it matters: Academics, diplomats, defense sector employees, and think tank researchers face targeted phishing campaigns that abuse legitimate platform features (app passwords, OAuth, device codes, WhatsApp linking) to bypass security controls; practitioners should educate high-risk users on recognizing social engineering lures impersonating state department and diplomatic organizations, audit linked devices and app passwords, and enforce app-specific password restrictions and advanced protection programs for at-risk personnel.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia
Google Threat Intelligence Group tracks three distinct Russian cyber espionage clusters (UNC6293, UNC7005, and UNC5976) targeting academics, diplomats, defense officials, and think tank personnel across Europe and the United States through sophisticated phishing campaigns that abuse legitimate authentication flows. The clusters employ app password phishing, OAuth phishing, device code phishing, WhatsApp device linking attacks, and malware distribution to compromise personal accounts without triggering two-factor authentication. UNC7005 and UNC5976 have escalated tactics by incorporating browser stealers, malware-as-a-service tools, and techniques to evade automated analysis, while also exploiting hospitality sector captive portals for initial access.
Why it matters: Academics, diplomats, defense sector employees, and think tank researchers face targeted phishing campaigns that abuse legitimate platform features (app passwords, OAuth, device codes, WhatsApp linking) to bypass security controls; practitioners should educate high-risk users on recognizing social engineering lures impersonating state department and diplomatic organizations, audit linked devices and app passwords, and enforce app-specific password restrictions and advanced protection programs for at-risk personnel.
- Source published
- First seen by Cybersecurity Tracker