Google Threat Intelligence Group reported that three Russian-linked espionage clusters—UNC6293, UNC7005, and UNC5976—targeted individuals of interest to Russia by abusing legitimate authentication workflows to steal access rather than relying on malware alone. The activity hit academia, NGOs, diplomatic organizations, defense, military, aerospace, and the defense industrial base, with UNC5976 particularly focused on targets connected to Ukraine and Armenia. GTIG said the campaigns leveraged techniques such as OAuth abuse, app passwords, and device-linking to capture authentication tokens after victims completed sign-in, making the operations harder to detect and attribute.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
Since August, UNC7005 has conducted OAuth phishing operations targeting Google and Microsoft accounts using cloud infrastructure. This marked an expansion of the cluster's phishing tradecraft beyond its previously described captive-portal and conference-lure activity.
In June 2026, Google observed UNC6293 using OAuth phishing, asking targets to share a full URL or verification code after a legitimate login to an external provider. Supplying the requested code gave the operators access to the victim's account.
In May and June 2026, UNC7005 used fake WhatsApp-themed pages to trick victims into approving legitimate device-linking requests for attacker-controlled devices. Successful linking gave the attackers access to victims' WhatsApp sessions, and some pages also presented fake voice-call, chat, or file-transfer options.
In April 2026, GTIG observed a malicious Excel plugin it named HEADRUSH, distributed via a domain impersonating a Ukrainian research institute. The sample ultimately led to an HTML Application downloader, and GTIG assessed the lure may have targeted a Ukrainian aerospace and imaging company.
Since June 2025, UNC6293 has impersonated U.S. State Department officials in app-password phishing campaigns. The operation tricked targets into creating attacker-known app passwords that enabled account access without triggering two-factor authentication.
In May 2021, Mandiant identified an APT29 operation using ICEBREAKER, a modified BOOMMIC/VaporRage variant, embedded in software mimicking an installer for a legitimate Ukrainian government application. The delivery chain was assessed as highly tailored for targeting Ukrainian government entities.
Historical phishing operations associated with ICE RELIC occurred between 2021 and 2024, targeting industries including academia, NGOs, diplomacy, and defense. GTIG later noted methodological overlap between these operations and the UNC6293 and UNC7005 clusters.
GTIG reported on UNC6293, UNC7005, and UNC5976 as distinct authentication-focused cyber espionage clusters with a Russian nexus. The report also assessed with moderate confidence that UNC6293 and UNC7005 are related to an ICE RELIC initial-access subcluster and published indicators tied to the operations.
Within about three months of the initial discovery and disruption, UNC5976 created at least twelve new domains and related infrastructure. GTIG assessed the cluster was also migrating part of its phishing infrastructure away from Google infrastructure to other providers.
GTIG disabled malicious cloud projects and took steps to disrupt UNC5976 phishing activity that used Google Cloud-hosted infrastructure to steal authentication tokens after victims authenticated. The operation redirected targets to Google Cloud project URLs where malicious scripts extracted tokens from URL parameters for operator retrieval.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 50 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcetheregister.com
Open sourcethehackernews.com
Open sourcecloud.google.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.