What happened
Google's Threat Intelligence Group published research on three suspected Russian espionage clusters — tracked as UNC6293, UNC7005, and UNC5976 — that hijack high-value accounts by abusing legitimate login features rather than classic fake password pages. Documented tactics include coaxing targets into generating app passwords, walking them through device-code sign-in flows, harvesting OAuth tokens after the victim completes a real login on a legitimate provider's page, and linking an attacker's device to a victim's WhatsApp account. Lures included fake conference invitations and impersonation of the U.S. State Department. UNC6293 is assessed to be a sub-cluster of APT29, the group tied to Russia's SVR foreign intelligence service. The campaigns are deliberately narrow — generally fewer than 100 targets and under 10 victims per operation — and focus on government, defense, aerospace, academia, and think tanks across the U.S. and Europe.
Why it matters for your business
The target list reads like a DC-area directory: think tanks, policy researchers, defense-adjacent firms, and the consultants and small contractors who work alongside them. But the technique is the bigger story for everyone else. These attacks succeed because the victim completes a genuine login on a genuine Microsoft, Google, or WhatsApp page — then hands over a code or approves a permission that quietly grants lasting access. Training that focuses on spotting fake URLs will not catch that, because nothing about the page is fake.
What to do about it
- Teach staff that verification codes, device-link requests, and app-permission prompts are as sensitive as passwords.
- Periodically review third-party app access and linked devices on email and messaging accounts.
- Move owners and anyone handling sensitive data to phishing-resistant MFA, such as hardware security keys.
