CYBERSECURITYTRACKER
TRACKING4,455 stories841 vuln stories
Permanent story citation

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4817

As cited

Citation snapshot as of .

threat intel

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three suspected Russian cyber espionage groups (UNC6293, UNC7005, and UNC5976) are exploiting legitimate Google OAuth and WhatsApp account linking features to compromise accounts of individuals in academia, aerospace, defense, government, and think tanks across Europe and the U.S. The attackers leverage these standard authentication flows to target specific individuals rather than attempting mass compromise.

Why it matters: Practitioners in government, defense, aerospace, academia, and policy organizations need to review and restrict OAuth integrations and third-party application access, as legitimate authentication mechanisms are being weaponized against high-value targets.

Source published
First seen by Cybersecurity Tracker

Source attribution