
Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia
Three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—are targeting individuals in academia, government, and defense to compromise accounts. These operations focus on abusing legitimate authentication flows such as OAuth, app passwords, and device linking.
Why it matters
Because these attacks often target personal rather than corporate accounts, organizations have a visibility gap that makes detecting breaches harder. This increases the risk of sensitive data theft for individuals in diplomatic, defense, and academic sectors.
The details
- UNC7005 used hospitality captive portals to redirect users to fake Microsoft login pages.
- Attackers deployed VIDAR and ATOMIC infostealers to steal browser-stored credentials and payment info.
- UNC6293 impersonated the US State Department using PDF lures for app password phishing.
Show entities and relationshipsHide entities and relationships
In this article
Products
Organizations
Topics
Key connections
Google owns Google OAuth
Google provides the Google OAuth authentication service.
Google owns Advanced Protection Program
Google offers the Advanced Protection Program for high-risk accounts.
Google is a partner of Anthropic
Google collaborated with Anthropic to track and disrupt threat actor operations.
Google is a partner of Lumen Technologies
Google collaborated with Lumen Technologies Black Lotus Labs to track threat operations.
Google is a partner of Polish Military Counterintelligence Service
Google collaborated with the Polish Military Counterintelligence Service (SKW) on threat tracking.
Google OAuth is built with OAuth
Google OAuth is built on the OAuth protocol.
Show 36 more connectionsShow fewer connections
Google Cloud uses OAuth
Google Cloud supports OAuth authentication flows.
Reliaquest is related to UNC7005
Reliaquest published threat analysis on captive portal redirects linked to UNC7005.
Volexity is related to UNC6293
Volexity documented diplomatic phishing operations conducted by UNC6293.
Citizen Lab is related to UNC6293
Citizen Lab reported on app password phishing operations conducted by UNC6293.
UNC6293 is a member of ICE RELIC
UNC6293 is assessed with moderate confidence to be a sub-cluster of ICE RELIC.
UNC7005 is a member of ICE RELIC
UNC7005 is assessed with moderate confidence as an initial access cluster connected to ICE RELIC.
UNC6293 is related to U.S. Department of State
UNC6293 impersonated the U.S. Department of State in app password and OAuth phishing campaigns.
UNC6293 uses App Passwords
UNC6293 uses app password phishing to bypass two-factor authentication.
UNC6293 incorporates OAuth phishing to obtain user verification codes.
UNC6293 uses Residential Proxies
UNC6293 heavily relies on commercial residential proxies for post-compromise activity.
UNC6293 possesses a suspected Russian nexus targeting individuals critical of Russia.
UNC7005 spoofed the GLOBSEC forum in Microsoft device code phishing operations.
UNC7005 is related to Finnish Operations Center
UNC7005 registered spoofed domains impersonating the Finnish Operations Center.
UNC7005 registered spoofed domains mimicking Outlook Web Access authentication resources.
UNC7005 is related to WhatsApp
UNC7005 conducted device linking phishing attacks spoofing WhatsApp.
UNC7005 served VIDAR infostealer malware to Windows targets.
UNC7005 served ATOMIC infostealer malware to macOS targets.
UNC7005 uses ENGINELIGHT
UNC7005 deployed ENGINELIGHT Go malware in targeted phishing campaigns.
UNC7005 deployed CHERRYPIE PowerShell infostealer malware in captive portal operations.
UNC7005 uses Device Code Phishing
UNC7005 conducts device code phishing operations targeting Microsoft and WhatsApp accounts.
UNC7005 uses Malware-as-a-Service
UNC7005 leverages Malware-as-a-Service infostealers in phishing operations.
UNC7005 uses Residential Proxies
UNC7005 heavily relies on commercial residential proxies for post-compromise activity.
UNC7005 is a threat cluster operating with a Russian nexus.
UNC7005 targeted personnel and used lure themes related to Ukraine.
CHERRYPIE is built with Large Language Models
CHERRYPIE contains code artifacts suggesting it was generated by a large language model.
UNC5976 deployed the HEADRUSH malicious Excel plugin against targets.
HEADRUSH is a malicious plugin designed for Microsoft Excel.
UNC5976 abuses cloud infrastructure for automated OAuth token collection.
UNC5976 is a suspected Russian cyber espionage cluster.
UNC5976 targeted Ukrainian aerospace and defense organizations.
UNC5976 geographic targeting has centered on Ukraine and Armenia.
ICE RELIC is related to Russia
ICE RELIC is a Russian state-sponsored cyber espionage threat group.
U.S. Department of State is located in United States
The U.S. Department of State is an executive agency of the United States.
Finnish Operations Center is related to NATO
The Finnish Operations Center supports Finnish companies in defense markets within NATO.
Finnish Operations Center is located in Finland
The Finnish Operations Center is located in Finland.
Polish Military Counterintelligence Service is located in Poland
The Polish Military Counterintelligence Service (SKW) is based in Poland.
Related events
Google Threat Intelligence Group Discloses Russian Cyber Espionage Clusters Abusing Authentication Flows
Get the weekly recap
The stories like this one, picked and explained — once a week, straight to your inbox.