Distinct Clusters Target Individuals of Interest to Russia
Google’s threat intelligence unit reports three suspected Russian cyber espionage clusters targeting academics, defense officials, and diplomats across the U.S. and Europe via phishing and OAuth abuse, including new clusters UNC7005 and UNC5976.
Google Cloud Threat Intelligence (GTIG) has identified three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—that are abusing legitimate authentication flows to target individuals in academia, aerospace and defense, government, and think tanks across Europe and the U.S. These groups employ persistent phishing campaigns, social engineering tactics, and malware to compromise accounts, often impersonating diplomatic or academic entities to gain unauthorized access.
UNC6293, assessed as a sub-cluster of ICE RELIC, has conducted app password phishing since June 2025, impersonating U.S. State Department officials to trick targets into setting insecure app passwords. The group has since expanded to OAuth phishing, requesting verification codes to bypass two-factor authentication. Targets are typically limited to fewer than five users per campaign, with lures focused on diplomatic themes or conferences.
UNC7005, first observed in February 2026, targets academia, diplomats, and nonprofits in Ukraine, Western Europe, and the U.S. The group uses app password and device code phishing, often reusing website templates from prior operations. In May and June 2026, UNC7005 deployed WhatsApp-themed phishing pages that recorded audio and video during fake calls and prompted users to download malicious files.
GTIG warns that these operations exploit legitimate authentication workflows, making them harder for users to detect. The clusters’ tactics include impersonating conferences, embedding malware, and adapting infrastructure to evade detection. Google urges targets to scrutinize unsolicited authentication requests and verify sender identities to mitigate risks.