Microsoft · Google · Russia · State Department · The Register
Russian snoops add OAuth abuse to targeted phishing campaigns
Compiled by KHAO Editorial — aggregated from 1 source + 4 references discovered via search. See llms.txt for citation guidance.
◌ Single Source
Don't click on that State Department meeting invite.
Key facts
- In June 2026, GTIG observed OAuth phishing where UNC6293 requested targets share either the full URL or ‘verification code’ after performing a legitimate login to an external provider,” Google
- Each campaign had fewer than 100 targets, and under 10 victims, the threat-intel team told The Register
- APT29 is probably best known for the 2020 SolarWinds hack, and infosec analysts from the UK and US governments, and the private sector, often link it to Russia's Foreign Intelligence Service (SVR)
- GTIG also asserts, with “moderate confidence,” that UNC7005 is another initial access group connected to APT2/Cozy Bear/Ice Relic, and the SVR
Summary
Google is tracking three distinct suspected Russian cyber-spy groups that are targeting individuals in academia, aerospace, defense, government agencies, and think tanks across Europe and the US. The UNC (unclassified) groups, as Google calls them, have been orchestrating these highly targeted campaigns since at least last year, and they remain ongoing. Each campaign had fewer than 100 targets, and under 10 victims, the threat-intel team told The Register. Despite the small numbers, if you work in government, NGOs, academia, or aerospace, you may be a target, and over the past few months the Russian snoops have adapted their attacks to abuse legitimate authentication flows. It also means that potential victims may not recognize these as phishing attempts.