Google details OAuth and WhatsApp account hijacking campaigns

Google Threat Intelligence Group has identified three suspected Russian cyber-espionage clusters exploiting legitimate authentication mechanisms to compromise selected targets in Europe and the United States. The clusters, UNC6293, UNC5976 and UNC7005, have targeted people in academia, aerospace and defence, government, diplomatic and think-tank roles.
The campaigns abuse Google OAuth, application-specific passwords, Microsoft device-code authentication and WhatsApp device linking. Google said the actors use persistent, adaptive phishing and sophisticated social engineering to gain access to personal accounts across multiple platforms.
OAuth phishing hides behind legitimate Google sign-in
UNC6293, assessed as a sub-cluster of Ice Relic, formerly known as APT29, Cozy Bear and Midnight Blizzard, has run narrowly focused phishing operations that typically target fewer than five people at a time. It has impersonated State Department officials and used diplomatic conferences and meetings as lures for application-password phishing.
As recently as June 2026, Google observed UNC6293 asking targets to send a full URL or verification code after completing a legitimate login with an external provider. Supplying that code can give the attacker access to the target account.
UNC5976 has used a related OAuth technique while automating token collection with cloud infrastructure. The group bought file-sharing-themed domains and created matching cloud projects. Its fake file-sharing pages display a login prompt after a short delay; selecting “Continue with Google” takes the victim to the genuine Google OAuth login page.
After authentication, victims are redirected to a Google Cloud project URL hosting scripts that retrieve tokens from the URL and stage them for later use. Google estimated that UNC5976 created at least 12 domains and related infrastructure from March 2026, all of which it has disrupted. The group subsequently moved phishing hosting to other providers.
WhatsApp linking turns a legitimate feature into an access path
UNC7005, also tracked as Storm-2945, emerged in Google’s reporting in February 2026. It has primarily targeted academic, diplomatic and nonprofit personnel in Ukraine, Western Europe and the US. Google believes UNC7005 and UNC6293 are connected to an Ice Relic subgroup focused on initial access operations.
In May and June, UNC7005 used WhatsApp-themed phishing pages that urged targets to link their accounts to an attacker-controlled device to join a secure call, chat or document share. The site asks for a phone number, generates a legitimate WhatsApp device-link request and presents the real QR code and linking code with instructions to complete the connection.
Once the account is linked, the page offers further options. Joining a voice call triggers JavaScript intended to record audio and video and send recordings to a command-and-control endpoint. An encrypted-chat option asks the target to copy presented credentials to a second URL, while the nature of the offered file download is unknown.
UNC7005 also began Google OAuth phishing with cloud infrastructure in early August. It registered domains mimicking the Finnish Operations Center and, between August 6 and 13, sent targeted messages to people in or connected to the European defence sector. Victims were directed through a genuine Google login flow and then to an attacker-controlled, unverified cloud project designed to steal tokens.
Wider campaigns reinforce the identity risk
The activity overlaps with CaptiveCrunch, which used captive Wi-Fi portals to redirect users toward attacker-controlled infrastructure. In the hotel and travel network threat described by hotel Wi-Fi token theft campaign, compromised gateways and DNS manipulation were used to pursue cloud tokens and deploy malware, illustrating how identity theft can extend beyond email-based lures.
Google said these authentication-focused operations make legitimate and malicious account access harder to distinguish. For organisations, the practical implication is to require independent verification for unexpected QR-code links, device codes, OAuth consent requests and verification-code requests, especially when they are framed as invitations, file shares or urgent communications.

