Three suspected Russian cyber espionage groups have been caught exploiting legitimate authentication systems to target individuals working in academia, aerospace, defense, governments, and think tanks across Europe and the United States. The threat clusters—designated UNC6293, UNC7005, and UNC5976—were documented in a report published today by Google Threat Intelligence Group (GTIG) researchers Gabby Roncone and Wesley Shields. The groups rely on sophisticated social engineering techniques to hijack personal accounts through persistent phishing operations.

UNC6293, which GTIG first identified in June 2025 alongside Citizen Lab, is believed to be a subdivision of Ice Relic, the Russian hacking operation also known as Cozy Bear and Midnight Blizzard. The group previously abused a Google feature called application-specific passwords to seize victim accounts and has since continued conducting small-scale phishing campaigns targeting fewer than five users at once while impersonating State Department officials. As recently as June 2026, the threat actor was observed conducting OAuth phishing by requesting targets to share either the complete URL or verification code after logging into an external provider. UNC5976, active since at least March 2026, has been found to use OAuth phishing techniques and automate token collection by abusing cloud infrastructure, creating at least 12 new domains and related infrastructure since March 2026, all of which have been disrupted by Google. The group also deployed a rogue Excel plugin codenamed HEADRUSH to deliver malware, with operational focus centered on the military, aerospace, defense industrial base, and NGOs.

UNC7005 emerged as the core focus of GTIG's research after being identified in February 2026, mainly targeting academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the U.S. In May and June 2026, the group conducted social engineering operations spoofing WhatsApp, luring targets into linking their accounts with an attacker-controlled device to join a purported secure call, chat, or document share. Once successfully linked, the phishing page served an additional prompt to either join a voice call—triggering JavaScript to record audio and video sent to a command-and-control endpoint—join an encrypted chat requiring login credentials on a secondary URL, or download a file of unknown nature. Around May 2026, UNC7005 augmented its capabilities with commodity infostealers like Vidar and Atomic to siphon data from Windows and macOS hosts targeting U.S.-based academics, diplomats, and researchers focused on Russia and former Soviet states. In early August 2026, the group began Google account OAuth phishing operations using cloud infrastructure, registering domains spoofing the legitimate Finnish Operations Center starting July 31, 2026, and sending targeted phishing emails to European defense industry contacts between August 6 and August 13, 2026.

These efforts connect to a campaign called CaptiveCrunch, documented by ReliaQuest and Microsoft late last month, which specifically targets captive Wi-Fi portals in locations such as hotels, conference centers, and airports to stealthily redirect users to attacker-controlled infrastructure. According to the report, the activity involves obtaining administrative access to Wi-Fi gateways to modify device configurations and using DNS poisoning to reroute regular web traffic through attacker-controlled infrastructure, with traffic manipulation attacks ongoing since early May 2026. The campaign can lead to deployment of a Go-based remote access trojan called CornFlake RAT or a PowerShell payload dubbed ChocoShell delivered via ClickFix lures, managed through a centralized web-based command-and-control panel known as FruitStone that's branded as legitimate cloud management software. Lumen Black Lotus Labs raised the possibility that the threat actor compromised several Managed Service Providers, then abused trust relationships with their clients in a supply chain attack, identifying approximately 70 victim IP addresses with 40 sending DNS requests to CaptiveCrunch command-and-control servers. "These clusters of Russia's authentication-focused cyber espionage operations target multiple types of authentication using legitimate features and infrastructure, ranging from app passwords to device linking," GTIG stated, noting that their creative abuse of legitimate features to compromise accounts makes tracking legitimate and malicious account access more challenging. The combination of these tactics not only enables quick-turnaround exfiltration operations but also presents opportunities to further phish targets from compromised, legitimate accounts. Organizations relying on conventional endpoint security may find their detection capabilities insufficient when adversaries weaponize the authentication layer itself. The campaign underscores how trust relationships—whether between employees and corporate login pages or managed service providers and their clients—can become vectors when attackers position themselves inside the authentication handshake rather than around it.