Google's GTIG links three Russian-nexus clusters to a coordinated campaign exploiting legitimate authentication flows against diplomats, academics, and defense-linked targets.

Intelligence Lead

Google's Threat Intelligence Group has confirmed that three Russian state-nexus hacking clusters are hijacking Google and WhatsApp accounts belonging to diplomats, academics, and defense-linked researchers by abusing legitimate OAuth and device-linking mechanisms rather than deploying malware. The shift toward authentic-looking authentication flows marks a deliberate tradecraft evolution designed to defeat both technical detection and user suspicion, and it signals that Moscow's HUMINT-adjacent cyber operations are becoming harder to distinguish from ordinary account activity.

Situation Report

GTIG researchers have assessed with high confidence that three distinct clusters, tracked as UNC6293, UNC7005, and UNC5976, share a Russian nexus and have been conducting parallel operations against individuals of strategic interest to the Kremlin. UNC6293 is assessed with moderate confidence as a sub-cluster of ICE RELIC, the group formerly designated APT29 and long associated with Russia's SVR foreign intelligence service. Reporting from Citizen Lab and Google Cloud's threat intelligence blog documents UNC6293 running app-specific-password phishing operations against prominent critics of Russia since at least mid-2025, with the campaign continuing into 2026.

UNC7005, also tracked as Storm-2945, was first identified in February 2026 and has concentrated on academic, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the United States. Analysts confirmed that UNC7005 began Google account OAuth phishing operations using attacker-controlled cloud infrastructure in early August 2026, redirecting targets through a legitimate Google authentication page before routing stolen tokens to an unverified attacker-owned cloud project. Separately, UNC5976 has been observed since March 2026 running an OAuth-token-theft operation with its own distinct infrastructure footprint.

A parallel WhatsApp-focused campaign, active in May and June 2026, directed targets to a spoofed landing page requesting a phone number, which in turn generated a genuine WhatsApp device-linking code for an attacker-controlled device. Targets who approved the linking request in their own WhatsApp client granted the attacker a persistent, authenticated session capable of reading message traffic without triggering conventional malware defenses. The Register and The Hacker News both independently corroborated GTIG's technical findings on August 20 and 21, 2026.

Background & Context

ICE RELIC's use of fake-conference lures and app-specific-password phishing against Russia critics has been documented since 2025, part of a broader pattern in which Kremlin-aligned services target academics, journalists, and policy figures assessed to hold access or influence relevant to Russian strategic interests. The current campaign extends that playbook by moving from credential phishing toward abuse of authentication mechanisms that platforms designed specifically to be more secure than passwords.

OAuth token theft and device-linking abuse are not new techniques in isolation, but their coordinated use across three distinct, Russia-nexus clusters targeting overlapping victim sets, government, military, aerospace, academic, and think tank personnel in Europe and the United States, indicates either shared tradecraft development or centralized tooling support. GTIG's decision to publish clustered attribution rather than a single campaign designation reflects the fragmented but coordinated structure increasingly typical of Russian cyber-espionage operations since 2024.

Analysis & Assessment

SpyWitness assesses with high confidence that this campaign represents a deliberate tradecraft pivot rather than an opportunistic technique. Abusing legitimate authentication flows, real OAuth consent screens, real WhatsApp linking codes, denies defenders the malware signatures and anomalous-login indicators that typically trigger detection, while simultaneously lowering the suspicion threshold for targets who see familiar platform interfaces rather than obvious phishing pages.

The overlapping victim profile across all three clusters, individuals with access to diplomatic, defense, or policy-relevant information, indicates this is HUMINT-adjacent collection rather than financially motivated activity. It is likely that additional Russian-nexus clusters will adopt similar authentication-abuse techniques in the coming months, given the demonstrated success against hardened, security-conscious targets. Whether UNC7005 and UNC5976 will be formally attributed to ICE RELIC or assessed as independent SVR- or FSB-linked services remains an open analytical question; GTIG's current moderate-confidence linkage should not be read as confirmed common tasking.