← Back to KHAO

Microsoft · Google · Russia · State Department ·

Russian snoops add OAuth abuse to targeted phishing campaigns

2 min read

Compiled by KHAO Editorial — aggregated from 1 source + 4 references discovered via search. See llms.txt for citation guidance.

◌ Single Source

A Microsoft Outlook app icon on a blue gradient background.

Don't click on that State Department meeting invite.

Key facts

Summary

Google is tracking three distinct suspected Russian cyber-spy groups that are targeting individuals in academia, aerospace, defense, government agencies, and think tanks across Europe and the US. The UNC (unclassified) groups, as Google calls them, have been orchestrating these highly targeted campaigns since at least last year, and they remain ongoing. Each campaign had fewer than 100 targets, and under 10 victims, the threat-intel team told The Register. Despite the small numbers, if you work in government, NGOs, academia, or aerospace, you may be a target, and over the past few months the Russian snoops have adapted their attacks to abuse legitimate authentication flows. It also means that potential victims may not recognize these as phishing attempts.

Read full article at The Register →

#Microsoft #Google #Russia #State Department