Russian snoops add OAuth abuse to targeted phishing campaigns

← Back to the feed

Russian snoops add OAuth abuse to targeted phishing campaigns

The Register · 9 hours ago

Google's Threat Intelligence Group says it is tracking three suspected Russian state-linked hacking groups running highly targeted phishing and OAuth-abuse campaigns against people in government, academia, aerospace, defence and think tanks across Europe and the US. The operations have been ongoing since at least last year, with some activity as recent as this month, and mark a shift towards abusing legitimate authentication flows to make social-engineering attempts appear more convincing and harder for victims to spot.

Each campaign is small in scale, with fewer than 100 targets and under 10 victims apiece, but Google warns anyone working in government, NGOs, academia or aerospace could be at risk. One group, UNC6293, tracked for almost two years and linked with moderate confidence to APT29 (Cozy Bear/Ice Relic, tied to Russia's SVR), poses as US State Department staff and has begun asking targets to share verification codes or URLs after a genuine login, granting attackers account access. Google also flagged two newer groups, UNC7005 and UNC5976; UNC7005, identified in February and targeting academic, diplomatic and nonprofit figures in Ukraine, Western Europe and the US, shares traits with UNC6293 but is tracked separately due to weaker operational security and its use of malware, including infostealers and keyloggers deployed via compromised public Wi-Fi captive portals.

  • Google tracks three Russian-linked groups phishing government, academic and aerospace targets
  • Attackers now abuse OAuth login flows to steal account access more convincingly
  • Campaigns are small-scale but ongoing, with activity seen as recently as this month

Art Culture Cybersecurity Elections Europe Politics Technology World

Read the full article at the source →