← Terug naar overzicht

Three suspected Russian cyber espionage clusters — UNC6293, UNC7005, and UNC5976 — have been observed abusing legitimate authentication flows, including Google OAuth and WhatsApp linking, to hijack accounts. The threat actors are targeting individuals in academia, aerospace and defense, government, and think tanks across Europe and the United States. The clusters engage in persistent and adaptive tactics to gain unauthorized access. The use of legitimate authentication mechanisms makes detection significantly more difficult. This campaign reflects a broader trend of state-sponsored actors exploiting trusted platforms to conduct espionage operations.

Technical details

Three suspected Russian cyber espionage clusters (UNC6293, UNC7005, UNC5976) are conducting persistent phishing campaigns targeting academia, aerospace and defense, governments, and think tanks in Europe and the U.S. UNC6293 (sub-cluster of Ice Relic/APT29/Cozy Bear/Midnight Blizzard): Conducts small-scope phishing targeting fewer than 5 users at a time, impersonating State Department officials. Uses app-specific password (ASP) phishing and OAuth phishing by requesting targets share full OAuth URLs or verification codes after legitimate login, allowing account takeover. Uses diplomatic and conference-themed lures. UNC5976 (active since at least March 2026): Uses OAuth phishing via fake file-sharing pages hosted on purchased domains. Pages display a pop-up with a 'Continue with Google' button redirecting to the legitimate Google OAuth login page. Post-authentication, victims are sent to a Google Cloud project URL running malicious scripts that retrieve and stage authentication tokens. Created 12+ new domains and infrastructure since March 2026; pivoted to other providers after Google disrupted their infrastructure. Also deploys a rogue Excel plugin called HEADRUSH that delivers an HTML Application (HTA) downloader, distributed via a fake domain impersonating a Ukrainian research institute. Targets military, aerospace, defense industrial base, NGOs/think tanks, primarily in Ukraine and Armenia. UNC7005 (aka Storm-2945, identified February 2026): Targets academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the U.S. Conducts app password phishing, device code phishing against Microsoft and WhatsApp accounts, and OAuth phishing. Uses wine/diplomatic event lures (linked to SPIKEDWINE campaign). WhatsApp compromise flow: phishing pages lure targets into linking their WhatsApp accounts to an attacker-controlled device by requesting phone numbers, generating a legitimate WhatsApp device link request, displaying QR/linking codes, then prompting victims to join a voice call (triggers JavaScript to record audio/video and send to C2), encrypted chat (prompts copying credentials for a secondary URL), or file download. Deploys commodity infostealers Vidar and Atomic (AMOS) against Windows and macOS targets via fake summit companion application downloads. In August 2026, began Google OAuth phishing spoofing the Finnish Operations Center (FOC), targeting European defense industry contacts between August 6-13, 2026. CaptiveCrunch Campaign (linked to UNC7005/Midnight Blizzard, documented by Microsoft and ReliaQuest): Targets captive Wi-Fi portals at hotels, conference centers, and airports since early May 2026. Attackers obtain administrative access to Wi-Fi gateways, modify configurations, and use DNS poisoning to reroute traffic through attacker-controlled infrastructure. Uses doppelganger domains mimicking Microsoft online services for adversary-in-the-middle (AitM) phishing abusing device code authentication flow in Microsoft Entra ID. Distributes malware disguised as browser/OS updates. Deploys: (1) CornFlake RAT - Go-based remote access trojan capable of system enumeration, file/keystroke collection, credential/session token theft, audio/video surveillance, removable media monitoring, and remote shell spawning; (2) ChocoShell (aka CHERRYPIE) - PowerShell-based infostealer delivered via ClickFix lure, steals Chrome app-bound encryption (ABE)-protected data, saved passwords, Microsoft 365 SSO tokens, and Wi-Fi credentials; likely LLM-generated. C2 infrastructure managed via FruitStone panel, branded as 'CloudSync Console' associated with 'Acuity Systems, Inc.', a single-page HTML/JavaScript application with no authentication, providing dashboard for managing compromised endpoints, building/deploying payloads, and reviewing collected data. Lumen Black Lotus Labs identified ~70 victim IPs: 40 sent DNS requests to CaptiveCrunch C2s, 30 communicated with AitM infrastructure, 1 interacted with ChocoShell C2. Possible MSP supply chain compromise identified, where attackers abused MSP trust relationships to reach client networks.

Mitigation steps

1. Be highly suspicious of any OAuth login prompts initiated from unfamiliar websites, especially those related to file sharing, diplomatic events, or conferences. Never share OAuth verification codes or full OAuth URLs with anyone. 2. Audit and review all authorized Google OAuth applications and third-party cloud project permissions associated with your Google accounts; revoke any unrecognized or unverified app authorizations. 3. Disable or limit the use of Google App-Specific Passwords (ASPs) where not required, and audit existing ASPs for unauthorized entries. 4. Monitor Microsoft Entra ID sign-in logs for suspicious device code authentication flows, especially from unusual locations or IP addresses. 5. Be cautious when linking WhatsApp devices; only do so via official WhatsApp settings and verify all QR code/linking requests are self-initiated. Monitor for unexpected linked devices in WhatsApp account settings and remove unauthorized devices immediately. 6. Avoid connecting to untrusted or public Wi-Fi networks (hotels, airports, conference centers) without VPN protection. Be alert to unexpected certificate warnings or login prompts when joining Wi-Fi networks (signs of captive portal manipulation or AitM attacks). 7. Implement phishing-resistant multi-factor authentication (e.g., hardware security keys/FIDO2) rather than relying solely on code-based MFA, as these are resistant to OAuth phishing. 8. Block or monitor for DNS poisoning indicators and unexpected DNS resolver changes on managed routers and network infrastructure. 9. Deploy endpoint detection solutions to identify infostealers such as Vidar, Atomic (AMOS), ChocoShell, and the CornFlake RAT. Look for unusual PowerShell execution, Go-based binaries, HTA file execution, and rogue Excel plugins. 10. Investigate any software or browser update prompts received while connected to captive portals or public Wi-Fi, as these may be malware delivery attempts. 11. MSPs should audit their client network access, review administrative access to Wi-Fi gateways, and monitor for unauthorized configuration changes indicative of supply chain compromise. 12. Rotate Microsoft 365 SSO tokens, browser session cookies, and Wi-Fi credentials on systems suspected of compromise. 13. Monitor for domains spoofing legitimate organizations (e.g., Finnish Operations Center, Ukrainian research institutes, NATO-related entities) in email links and web traffic. 14. Use Google's advanced protection program or equivalent for high-risk users (academics, diplomats, government officials, researchers focused on Russia/former Soviet states). 15. Report suspicious OAuth authorization requests, WhatsApp device linking attempts, and phishing emails to Google, Microsoft, and relevant security teams.

Affected products

  • Captive Wi-Fi portals (hotels
  • Google Accounts (App-Specific Passwords feature)
  • Google Chrome (App-Bound Encryption)
  • Google Cloud Projects
  • Google OAuth
  • Managed Service Providers (MSPs)
  • Microsoft 365 (SSO tokens)
  • Microsoft Entra ID (device code authentication flow)
  • WhatsApp (device linking feature)
  • Wi-Fi routers/gateways
  • Windows
  • airports)
  • conference centers
  • macOS

Related threat actors

  • Cozy Bear
  • Ice Relic (formerly APT29)
  • Midnight Blizzard
  • UNC5976
  • UNC6293 (sub-cluster of Ice Relic/APT29/Cozy Bear/Midnight Blizzard)
  • UNC7005 (aka Storm-2945)

IOC's

Domains spoofing Finnish Operations Center (FOC) registered starting July 31, 2026, File-sharing-related domain names used by UNC5976 for OAuth phishing pages, 12+ domains created by UNC5976 since March 2026 (since disrupted by Google), Fake domain impersonating Ukrainian research institute (used for HEADRUSH distribution), Fake domain spoofing summit related to 'resolution in support of Ukraine', Doppelganger domains mimicking Microsoft online services, FruitStone C2 panel branded as 'CloudSync Console' associated with 'Acuity Systems, Inc.', Malware: CornFlake RAT (Go-based), Malware: ChocoShell / CHERRYPIE (PowerShell-based infostealer), Malware: HEADRUSH (rogue Excel plugin delivering HTA), Infostealers: Vidar, Atomic (AMOS), Campaign: CaptiveCrunch, Campaign: SPIKEDWINE, Approximately 70 victim IP addresses identified by Lumen Black Lotus Labs, Unverified Google Cloud project URLs used to steal authentication tokens, Phishing pages with 'Continue with Google' OAuth pop-up dialogs, ClickFix lures delivering ChocoShell, Commercial residential proxies used for post-compromise activity

Categories

  • Cloud & Virtualization
  • Data Breach & Exfiltration
  • Email & Messaging
  • Identity & Access
  • Network Infrastructure
  • Ransomware & Malware
  • Supply Chain & Dependencies