UNC6293 is a Russian state-linked cyber espionage cluster assessed with moderate confidence to be a sub-cluster of ICE RELIC, also widely tracked as APT29, Cozy Bear, and Midnight Blizzard, and associated with the Russian Foreign Intelligence Service (SVR). The cluster appears focused on initial access and account compromise operations against high-value individuals rather than broad enterprise intrusion at scale. UNC6293 is known for low-volume, highly tailored social-engineering campaigns that abuse legitimate authentication workflows instead of relying on malware or exploit chains. Its most characteristic tradecraft involves impersonating trusted institutions, including U.S. State Department personnel, to persuade targets to generate and surrender Google application-specific passwords, enabling persistent access that bypasses normal multi-factor authentication protections. The group has also used OAuth phishing and attempted abuse of Microsoft device-code authentication flows to induce victims to grant attacker-controlled access through legitimate sign-in processes. Reporting further indicates the actor seeks long-lived access to mailboxes and documents and uses commercial residential proxies during post-compromise activity. Targeting has centered on prominent academics, journalists, critics of Russia, researchers, think-tank personnel, diplomats, and other individuals of intelligence interest, including people focused on Russia, Ukraine, and former Soviet states. Observed operations were typically small in scope, often targeting only a handful of users at a time, but were persistent, adaptive, and patient, with repeated re-engagement attempts and evolving lure themes. UNC6293 has also used tailored calendar invitations and virtual meeting pretexts to support credential and delegated-access theft. The cluster overlaps operationally with another Russian espionage cluster, UNC7005, and both have been assessed as related to an ICE RELIC initial-access subgroup. UNC6293 exemplifies a broader Russian intelligence pattern of abusing legitimate identity and cloud authentication features to make malicious access resemble normal user activity and complicate detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
44 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Authentication-focused cyber espionage cluster conducting small-scope, highly selective phishing campaigns, including app password phishing and OAuth phishing, to compromise personal accounts of individuals of interest.
Focuses on gaining durable access to mailboxes/documents by persuading targets to use legitimate authentication features (ASPs, device-code flows) and delegated access mechanisms; likely to adapt to MCP-style environments by obtaining user/admin authorization for integrations and then accessing data via normal APIs.
Credential theft / account takeover via highly targeted social engineering that convinces victims to generate and surrender Google app-specific passwords (ASPs), enabling MFA bypass and Gmail access.
Highly targeted, patient social-engineering campaign impersonating the U.S. State Department to compromise individual researchers/critics of Russia by inducing victims to generate and share Google app-specific passwords (ASPs), effectively bypassing MFA protections.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.