Google Uncovers Russian Espionage Clusters Exploiting OAuth, WhatsApp and Fake Diplomatic Conferences + Video

Listen to this Post

Featured ImageA New Era of Espionage Is Hiding Behind Real Logins

Cyber espionage is entering a far more dangerous phase, one where seeing a legitimate login page may no longer be enough to reassure a potential victim.

Google Threat Intelligence Group has revealed ongoing activity involving three suspected Russian cyber espionage clusters, tracked as UNC6293, UNC7005 and UNC5976. The operations have targeted high-value individuals across Europe and the United States, including government officials, diplomats, academics, think-tank researchers, aerospace personnel, defense employees and other individuals considered strategically valuable for intelligence collection.

What makes these campaigns particularly concerning is not simply the use of phishing, malware or impersonation. The attackers are increasingly abusing legitimate authentication systems.

A victim may authenticate through a real Google, Microsoft or WhatsApp service and still unknowingly provide attackers with a pathway into their account.

That is the uncomfortable reality behind these campaigns.

The fake website may be fake, but the authentication process itself can be completely genuine.

The Original Report in Summary

According to Google Threat Intelligence Group, the three clusters have developed different approaches to targeting individuals connected to governments, diplomacy, defense, research and geopolitical affairs.

UNC6293 has reportedly impersonated U.S. State Department personnel and used diplomatic meetings, professional engagements and upcoming conferences as convincing phishing lures. Google assesses with moderate confidence that the cluster is connected to ICE RELIC, an activity set historically associated with the threat landscape surrounding APT29, Cozy Bear and Midnight Blizzard.

Meanwhile, UNC7005 has focused on Microsoft device-code authentication and WhatsApp’s device-linking functionality. The group reportedly created convincing pages that offered victims access to secure calls, encrypted conversations or shared content.

Victims interacting with those pages could unknowingly connect their WhatsApp accounts to attacker-controlled devices.

UNC7005 has also used fake diplomatic invitations and conference infrastructure, including pages impersonating the GLOBSEC forum. Google further observed the use of commodity information-stealing malware, including VIDAR for Windows environments and ATOMIC against macOS targets.

The infrastructure associated with UNC7005 was also linked by Google to campaigns involving compromised captive Wi-Fi portals at hotels and conference locations.

UNC5976, meanwhile, has used OAuth phishing through fake file-sharing services and cloud infrastructure designed to capture authentication tokens. Its targeting reportedly includes military, aerospace, defense-industrial and NGO interests, particularly organizations and individuals connected to Ukraine and Armenia.

Together, the campaigns reveal a wider evolution in cyber espionage.

The attackers are no longer relying exclusively on stealing passwords.

They are increasingly attempting to manipulate the authorization systems that sit behind modern digital identity.

UNC6293 Turns Diplomacy Into a Phishing Weapon

Diplomatic communication is built on trust, urgency and exclusivity.

A message inviting someone to a private meeting, policy discussion or international conference can appear completely believable, particularly when the recipient regularly communicates with government officials and international organizations.

UNC6293 appears to have taken advantage of exactly that environment.

By impersonating U.S. State Department personnel and using professional meetings or upcoming events as lures, the operators attempted to create scenarios where the victim would feel that responding quickly was both normal and necessary.

This is a powerful social-engineering strategy.

Traditional phishing often depends on fear.

Modern espionage phishing increasingly depends on credibility.

A fake tax warning may trigger suspicion.

A message about an upcoming diplomatic meeting may trigger curiosity.

That difference matters.

The more the lure resembles the

From App Passwords to OAuth, the Attack Surface Is Changing

One of the most significant findings is the apparent evolution from app-password phishing toward OAuth-based attacks.

OAuth is widely used to allow applications and services to access accounts without requiring users to hand over their primary passwords directly.

That model has major security benefits when implemented correctly.

However, the same trust model can become dangerous when attackers manipulate the user into authorizing access for a malicious or attacker-controlled application.

Instead of saying, “Give us your password,” the attacker may effectively say, “Authorize this application.”

The victim may then complete a legitimate authentication process.

The login may occur on a genuine service.

Multi-factor authentication may even succeed.

But the final authorization can still benefit the attacker.

This is why OAuth phishing deserves serious attention.

Security awareness programs often teach users to inspect URLs and avoid entering passwords into suspicious websites.

Those habits remain important.

But they do not fully protect users when the authentication window belongs to a legitimate provider.

Why Real Authentication Can Still Lead to Account Compromise

The modern internet has trained users to trust familiar authentication providers.

If they see a legitimate Google or Microsoft login page, they may feel confident that the interaction is safe.

Normally, that confidence is understandable.

The problem begins after authentication.

Attackers can attempt to manipulate victims into approving access, submitting authorization URLs or providing verification codes that allow an operation to continue.

In these situations, the password may never be directly stolen.

The victim may successfully authenticate.

The account may even remain protected by multi-factor authentication.

Yet an attacker can potentially obtain an authorization mechanism that allows continued access.

This changes the psychology of phishing defense.

The question is no longer simply, “Is this login page legitimate?”

Defenders must also ask, “What exactly am I authorizing, and who requested this authorization?”

UNC7005 Targets Microsoft Authentication and WhatsApp Linking

UNC7005 demonstrates how cyber espionage operators are expanding beyond conventional email compromise.

Google reported that the cluster abused Microsoft device-code authentication and WhatsApp’s device-linking functionality.

Both mechanisms are designed to make legitimate services easier to use.

Device-code authentication can help users sign into services on devices where entering credentials directly is inconvenient.

WhatsApp device linking allows users to connect additional devices to their account.

The functionality itself is not inherently malicious.

The danger comes from social engineering.

Attackers can create a fake page and convince a victim that linking a device is necessary to join a secure call, access encrypted content or continue a professional conversation.

The victim may believe they are completing a routine security process.

Instead, they may be linking an attacker-controlled device.

Fake Secure Communications Are Becoming a Powerful Lure

The promise of secure communication is particularly effective against diplomats, government officials, journalists, researchers and defense personnel.

A message offering an encrypted call or secure chat sounds appropriate for sensitive conversations.

That is precisely why the technique can work.

Attackers do not always need to invent something suspicious.

Sometimes the most convincing lure is a service the victim genuinely expects to use.

A fake page advertising secure communications can exploit the user’s existing security awareness.

Ironically, people who are actively trying to communicate securely may become attractive targets for campaigns pretending to improve their security.

This is one of the most dangerous aspects of modern social engineering.

Security itself can become the lure.

Fake Conferences Create the Perfect Espionage Environment

UNC7005 also reportedly used fake diplomatic and conference invitations, including infrastructure impersonating GLOBSEC.

Conferences are particularly useful environments for espionage campaigns.

They bring together government officials, academics, researchers, defense experts, technology specialists and journalists.

They also generate large volumes of legitimate email.

Invitations.

Registration forms.

Speaker schedules.

Hotel information.

Shared documents.

Messaging groups.

Video meetings.

Every one of these activities can be imitated.

A carefully designed fake conference page does not need to look like a generic phishing website.

It can look like part of a professional ecosystem that the victim already trusts.

That makes detection significantly more difficult.

Hotels and Conference Wi-Fi May Become an Intelligence Battlefield

Google also connected infrastructure associated with UNC7005 to a recently disclosed campaign involving compromised captive Wi-Fi portals at hotels and conference venues.

This finding highlights another important shift.

Cyber espionage is increasingly blending digital operations with physical environments.

A conference attendee may receive an invitation before the event.

They may encounter a suspicious Wi-Fi portal during travel.

They may receive a message about accessing shared documents.

Later, they may be invited to a secure chat.

Each individual event may appear normal.

Together, however, they can form a coordinated intelligence operation.

The modern espionage campaign is no longer necessarily limited to a single phishing email.

It can follow the target through multiple devices, networks and communication platforms.

VIDAR and ATOMIC Show a Cross-Platform Strategy

Google reported the use of VIDAR against Windows systems and ATOMIC against macOS targets.

This matters because high-value espionage operations cannot assume that every target uses the same operating system.

Government and enterprise environments are increasingly mixed.

A policy researcher may work from a Windows laptop.

A diplomat may use macOS.

A researcher may move between corporate systems, personal devices and mobile platforms.

Attackers are adapting accordingly.

Commodity malware also provides operators with flexibility.

A sophisticated espionage campaign does not always require an entirely custom malware framework.

In some cases, readily available information stealers can provide enough capability to collect browser data, credentials, session information or other valuable artifacts.

The distinction between “advanced attackers” and “commodity tools” is therefore becoming less useful.

Sophisticated operations can still use widely available malware.

UNC5976 Focuses on Tokens Rather Than Passwords

UNC5976 represents another example of the

The group reportedly conducted OAuth phishing through fake file-sharing services and cloud infrastructure intended to capture authentication material.

Cloud collaboration has become essential for governments, NGOs, research organizations and defense-related industries.

People constantly receive links to documents.

They share reports.

They exchange files.

They collaborate across organizational boundaries.

That creates an enormous opportunity for attackers.

A fake file-sharing notification may look completely ordinary.

The victim clicks.

The authentication flow begins.

The service may appear familiar.

The attacker waits for the victim to authorize something they do not fully understand.

That is enough to create serious risk.

Ukraine and Armenia Remain High-Value Intelligence Targets

Google said UNC5976 targeted military, aerospace, defense-industrial and NGO interests, particularly those involving Ukraine and Armenia.

The targeting reflects the geopolitical importance of information connected to regional security, military capabilities and international policy.

Cyber espionage campaigns often focus on the people surrounding a conflict rather than only the organizations directly involved in it.

Researchers.

Consultants.

Journalists.

NGO employees.

Former officials.

Defense contractors.

Academic specialists.

All of them may possess information that is useful when combined with other intelligence sources.

This means the security perimeter of a sensitive organization can extend far beyond its official network.

Personal accounts may become as strategically valuable as corporate accounts.

Personal Accounts Are Becoming the Weakest Link

Enterprise security teams can monitor corporate endpoints.

They can deploy endpoint detection.

They can enforce conditional access.

They can monitor suspicious authentication behavior.

But personal accounts often exist outside that security perimeter.

A diplomat may use a personal email account for non-classified communication.

A researcher may use private cloud storage.

An academic may communicate through encrypted messaging applications.

A defense specialist may maintain personal devices that are not managed by an employer.

Attackers understand this.

If a highly protected corporate account is difficult to compromise, a personal account may provide an alternative route to valuable information.

The problem is not always direct access to classified material.

Sometimes the most useful intelligence comes from contacts, calendars, conversations, documents and relationship networks.

Encrypted Messaging Does Not Eliminate Social Engineering

Encryption protects the content of communications in transit and, depending on the platform, can provide strong protections for stored messages.

However, encryption cannot protect a user who is manipulated into authorizing an attacker-controlled device.

This is a crucial distinction.

Cryptography can secure data.

It cannot always protect decisions.

If the legitimate account owner approves access, links a device or shares a verification code under false pretenses, the attacker may gain access without breaking encryption.

This is why modern security must combine technology with behavioral awareness.

The strongest cryptographic system can still be undermined by a convincing story.

Multi-Factor Authentication Is Necessary, but Not Always Sufficient

The campaigns also demonstrate an uncomfortable truth about multi-factor authentication.

MFA remains one of the most important defenses against traditional credential theft.

Organizations should absolutely continue to use it.

However, MFA does not automatically prevent attacks involving malicious authorization, stolen session material or device-linking abuse.

Security teams must therefore move beyond a simple model of:

Password compromised equals bad.

MFA completed equals safe.

Real-world authentication is more complicated.

An attacker may not need to defeat MFA.

They may simply manipulate the victim into completing it.

That is a fundamental difference.

The user becomes part of the authorization chain.

Why These Campaigns Are Difficult for Traditional Security Tools

Traditional security monitoring often focuses on suspicious malware, malicious domains and unusual login locations.

OAuth and device-linking attacks can complicate this picture.

The victim may interact with a legitimate authentication provider.

The login event may look normal.

The authentication may originate from the

The user may successfully complete MFA.

From a narrow technical perspective, everything may appear legitimate.

The malicious activity may only become visible after the attacker receives an authorization token, links an additional device or begins using a newly approved session.

This requires security teams to monitor more than failed logins.

They need visibility into consent events, application permissions, token usage, device registrations and unusual changes to account access.

The Attack Is No Longer Always a Fake Login Page

For years, phishing awareness focused heavily on detecting fake login pages.

That guidance remains useful.

But modern identity attacks increasingly exploit legitimate infrastructure.

The attack may begin with a fake invitation.

It may then redirect the victim to a genuine authentication provider.

The victim enters their credentials on a legitimate domain.

They complete MFA.

The attacker succeeds because the victim was manipulated before or after authentication.

This is phishing without the traditional password-stealing moment.

And that makes it far more difficult to explain in a simple awareness training slide.

Organizations Need to Monitor Authorization, Not Just Authentication

Authentication answers one question.

Who are you?

Authorization answers another.

What are you allowed to do?

The difference is becoming increasingly important.

Security teams should monitor when new applications receive access to sensitive accounts.

They should investigate unusual consent grants.

They should review connected devices.

They should examine whether authentication tokens are being used from unexpected environments.

And they should reduce unnecessary application permissions.

An account protected by a strong password and MFA can still face risk if the authorization layer is not properly controlled.

Identity security is no longer only about stopping unauthorized logins.

It is also about detecting unauthorized access that was granted through deception.

What Undercode Say:

The Biggest Threat Is Not a Broken Authentication System

The most alarming part of

They are abusing trust in authentication.

That distinction should fundamentally change how organizations think about phishing.

For years, security teams told employees to check the domain.

Now the domain may actually belong to Google or Microsoft.

For years, users were told to enable MFA.

Now attackers may manipulate them into approving a legitimate authentication process.

For years, organizations focused on protecting passwords.

Now access tokens, application permissions and linked devices are becoming equally important.

The attack surface has moved.

It is moving from credentials toward identity relationships.

The real question is not simply whether a user logged in.

The real question is what happened after the login.

Did the user authorize a new application?

Did they connect an unknown device?

Did they provide a verification code?

Did they approve access they did not understand?

These events can be far more important than the password itself.

The conference-themed campaigns are also strategically significant.

A fake invoice can target thousands of people.

A fake diplomatic invitation can target a handful of individuals with extremely high intelligence value.

That allows attackers to invest more time into research and impersonation.

They can study public speaking schedules.

They can examine conference announcements.

They can identify professional relationships.

They can imitate real organizations.

They can create infrastructure that appears connected to an upcoming event.

The result is highly contextual social engineering.

This is where traditional phishing awareness often fails.

People are trained to identify obviously suspicious messages.

Sophisticated espionage campaigns are designed to look professionally ordinary.

The use of personal accounts makes the situation even more complicated.

Corporate security teams may have limited visibility into private email, cloud storage and messaging applications.

Yet those environments may contain professional conversations, contact lists and documents.

Attackers do not necessarily need to compromise the most protected system.

They only need to find the least protected path to useful intelligence.

Another important lesson is that encryption is not the same as account security.

Encrypted communications remain valuable.

But encryption cannot stop a victim from connecting an attacker’s device to their account.

The security community must therefore stop presenting technologies as magical shields.

Every security control has a boundary.

OAuth phishing attacks also demonstrate why identity monitoring needs to become more intelligent.

A successful login should not automatically end the security investigation.

In some cases, it should begin one.

The future of account security will depend heavily on behavioral analysis.

Which applications does this user normally authorize?

Which devices are normally connected?

Where are tokens being used?

How quickly did permissions change?

Does the authorization pattern match the

These questions will become increasingly important.

Defenders should also expect attackers to combine multiple platforms.

An email invitation may lead to a cloud document.

The document may trigger OAuth authorization.

A follow-up message may arrive through WhatsApp.

The target may then encounter related infrastructure while connecting to hotel Wi-Fi.

This creates a multi-stage social-engineering ecosystem.

Blocking one malicious domain may not stop the entire operation.

Organizations need correlation across identity, email, endpoints, messaging and network activity.

The human element remains central.

But blaming users is not an effective solution.

If a phishing campaign is highly targeted, professionally researched and built around legitimate authentication systems, even experienced users can be deceived.

The responsibility must therefore be shared.

Users need awareness.

Platforms need stronger abuse detection.

Organizations need identity monitoring.

Administrators need to reduce unnecessary permissions.

And security teams need to treat suspicious authorization events as seriously as suspicious passwords.

The old model of phishing is fading.

The new model is authorization deception.

That is a much harder problem to solve.

Google Identified Three Separate Suspected Clusters

✅ Google Threat Intelligence Group reported activity involving UNC6293, UNC7005 and UNC5976 targeting individuals of intelligence interest. The campaign details described in the report support the existence of distinct tracked activity clusters and different operational techniques.

The Operations Abused Legitimate Authentication Workflows

✅ The central finding is that attackers can exploit legitimate authentication and authorization mechanisms, including OAuth and device-linking processes. A genuine login does not automatically mean the overall interaction is safe.

The APT29 Connection Requires Careful Wording

✅ Google assessed with moderate confidence that UNC6293 is a sub-cluster connected to ICE RELIC, which has historical associations with activity known as APT29, Cozy Bear and Midnight Blizzard. Moderate confidence is an intelligence assessment, not absolute attribution.

Prediction

(+1) Identity Security Will Become a Primary Battlefield

OAuth permissions, session tokens and application consent events will receive significantly more attention from enterprise security teams.

Messaging platforms and collaboration tools will likely introduce stronger warnings around new device linking and unusual authorization requests.

Security awareness programs will increasingly teach users to question authorization requests, not only suspicious password pages.

(-1) Social Engineering Will Become More Convincing

Attackers will continue using real conferences, professional events and geopolitical developments to create highly believable lures.

Traditional MFA may provide a false sense of security when victims are manipulated into approving legitimate authentication or authorization workflows.

Personal accounts and unmanaged devices may become increasingly attractive targets because they often exist outside enterprise monitoring.

Deep Analysis
Investigating Suspicious OAuth and Identity Activity

Security teams can begin by reviewing identity logs for unusual authorization behavior.

On Linux systems, analysts can use command-line tools to search exported authentication and audit logs:

grep -iE "oauth|consent|authorize|token" authentication.log

Investigators can identify unusual IP addresses associated with authentication events:

awk '{print $1}' authentication.log | sort | uniq -c | sort -nr

Security teams can search for recently registered or connected devices:

grep -iE "device|linked|registered" authentication.log | tail -n 50

When analyzing downloaded files or suspected phishing artifacts, defenders can calculate cryptographic hashes:

sha256sum suspicious_file

Network connections from a potentially compromised Linux endpoint can also be reviewed:

ss -tulpn

Analysts can examine active processes for unusual applications:

ps aux --sort=-%mem | head -n 20

To search system logs for suspicious authentication activity, defenders can use:

journalctl --since "24 hours ago" | grep -iE "login|oauth|token|device"

Organizations should also compare authorization events with normal user behavior.

A new application requesting broad mailbox access deserves investigation.

A new device appearing immediately after a suspicious conference invitation deserves investigation.

An authentication token suddenly being used from an unexpected environment deserves investigation.

The technical lesson is simple.

Do not monitor only failed authentication attempts.

Monitor successful authentication followed by unusual authorization.

That is where the next generation of phishing attacks may be hiding.

The fake page may be easy to identify.

The more dangerous part may happen after the victim leaves it.

The authentication may be real.

The account may be real.

The MFA approval may be real.

And the attacker may still walk away with access.

Google’s findings show why cyber espionage is increasingly becoming an identity war.

The battlefield is no longer limited to malware, exploits and stolen passwords.

It is now built around trust.

Who you believe.

What you authorize.

Which device you connect.

And whether you notice that a perfectly legitimate login was part of a much larger deception.

▶️ Related Video (84% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.github.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube