IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Google flags Russian spies abusing real login features

Google flags Russian spies abusing real login features

Fri, 21st Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Google has identified three suspected Russian cyber espionage groups targeting people in academia, defence, government and think tanks. The clusters abuse legitimate authentication processes to gain access to accounts.

Its Threat Intelligence Group said the activity centres on UNC6293, UNC7005 and UNC5976, which it tracks as separate operations with overlapping tactics but different infrastructure and tradecraft. Targets are concentrated across Europe and the United States, with some activity focused on Ukraine and Armenia.

The campaigns rely less on traditional fake login pages than on the misuse of real account features, including app passwords, device codes, OAuth permissions and device-linking tools. That can make attacks look more credible because users are often interacting with a genuine authentication page or a recognised platform workflow.

Google linked two of the clusters, UNC6293 and UNC7005, with moderate confidence to a sub-cluster of ICE RELIC, the threat actor better known as APT29. It assessed with high confidence that all three clusters have a Russian nexus based on their targeting, themes and methods.

Three clusters

UNC6293 has carried out small, tightly focused phishing efforts aimed at people seen as relevant to Russian interests. The group has repeatedly impersonated US State Department officials and tried to persuade targets to create app passwords, which attackers could then use to access accounts without needing two-factor authentication.

In earlier cases, attackers asked targets to send the app password by email. More recent operations shifted tactics, directing victims to enter the code into a site designed to look legitimate. The group also added OAuth phishing by asking targets to hand over a full URL or a verification code after a real login to an external provider.

UNC7005, also known as STORM-2945, appears broader in scope and less disciplined in its operational security, according to the findings. It has targeted people in academia, diplomacy and non-profit organisations across Ukraine, Western Europe and the US, using app password phishing, Microsoft device code phishing, WhatsApp lures and malware delivery.

One strand of UNC7005's activity used fake event invitations and registration pages that copied the look of legitimate organisations. Some of those pages attempted to fingerprint visitors' systems and detect automated analysis tools before showing phishing content.

Another strand involved WhatsApp. Targets were tricked into linking their WhatsApp accounts to an attacker-controlled device under the pretence of joining a secure call, chat or document exchange. Once the link was established, the page could present further prompts, including a fake voice call that triggered malicious code to record audio and video from the victim's device.

Malware use

UNC7005 also ran a broader phishing campaign against mainly US-based academics, diplomats and researchers focused on Russia and former Soviet states. Victims who clicked through from a Windows device were served VIDAR, an information-stealing malware strain, while macOS users were served ATOMIC, also known as AtomicStealer.

Google also tied UNC7005 to infrastructure used in the hospitality captive portal attacks that have drawn attention from other security groups. In those incidents, users on hotel and conference centre networks were redirected from captive portals to attacker-controlled pages impersonating Microsoft authentication services.

It said it had been tracking related infrastructure since late April and had added domains to Safe Browsing blocklists as they were activated. Links between domains, registration details, IP addresses and malware infrastructure connected the captive portal campaign to UNC7005's broader account theft and malware operations.

UNC5976, by contrast, is treated as a separate Russian espionage cluster. The group has focused on OAuth phishing backed by automation and cloud-hosted infrastructure, often using file-sharing-themed domains that directed users to a fake document-sharing page before prompting them to continue with a Google login.

After a victim authenticated, attackers redirected them to a cloud project URL where malicious scripts collected the authentication token from the browser address. Google said it disrupted those cloud projects, but the group responded by creating at least a dozen new domains and later began shifting some hosting away from Google infrastructure.

The same cluster has also been linked to malware. Google said it observed a malicious Excel plugin, which it calls HEADRUSH, distributed through a domain impersonating a research institute in Ukraine and possibly aimed at a Ukrainian aerospace and imaging company.

Personal accounts

A notable feature of the operations is the emphasis on personal rather than corporate accounts. That creates a blind spot for employers and institutions because compromise may happen outside managed systems and official email domains.

Google said the use of messaging applications for first contact, alongside legitimate authentication features, makes the campaigns harder to spot and can help attackers move quickly from one compromised account to another. It also warned that app passwords are not intended for identity verification and said users should remove any they no longer need.

Google has disabled known actor accounts, acted against infrastructure hosting malicious content and worked to secure affected users where possible. It added that high-risk users should treat unsolicited invitations and login requests with caution, even when the person or organisation appears familiar.

It also said UNC7005's use of malware-as-a-service tools and large language models in parts of its malware activity has complicated attribution and shortened the time needed to prepare new operations.