As cited
Citation snapshot as of .
threat intel
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three suspected Russian cyber espionage groups (UNC6293, UNC7005, and UNC5976) are exploiting legitimate Google OAuth and WhatsApp account linking features to compromise accounts of individuals in academia, aerospace, defense, government, and think tanks across Europe and the U.S. The attackers leverage these standard authentication flows to target specific individuals rather than attempting mass compromise.
Why it matters: Practitioners in government, defense, aerospace, academia, and policy organizations need to review and restrict OAuth integrations and third-party application access, as legitimate authentication mechanisms are being weaponized against high-value targets.
- Source published
- First seen by Cybersecurity Tracker