Google Threat Intelligence Group reported on three distinct suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—abusing legitimate authentication mechanisms to target government, defense, and academic personnel.
Aug 20, 2026
11d agoKey Details
- UNC6293, a sub-cluster of ICE RELIC (formerly APT29), conducted app password and OAuth phishing campaigns impersonating the U.S. Department of State.
- UNC7005 conducted device code phishing, hospitality captive portal redirects, and deployed MaaS infostealers including VIDAR and ATOMIC as well as LLM-generated CHERRYPIE malware.
- UNC5976 abused cloud infrastructure for OAuth token theft and deployed the HEADRUSH malicious Excel plugin against Ukrainian aerospace and defense organizations.
- Google took actions to disable malicious cloud projects, add infrastructure to the Safe Browsing blocklist, and coordinate disruption with industry and government partners.