2 min read

Russian-linked hackers turn Google and WhatsApp logins into phishing traps

Vlad CONSTANTINESCU

August 21, 2026

Russian-linked hackers turn Google and WhatsApp logins into phishing traps

Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features to compromise personal accounts of people in sensitive sectors across Europe and the US, Google says.

Key takeaways

  • Google is tracking UNC6293, UNC7005 and UNC5976, which it assesses with high confidence to have a Russian nexus
  • The campaigns abuse legitimate Google OAuth, app-password and device-linking workflows rather than software vulnerabilities
  • UNC7005 has also used WhatsApp device linking to attach attacker-controlled devices to victims’ accounts
  • Targets include academics, diplomats, defense personnel, government-linked users and think-tank researchers

Legitimate sign-in pages become phishing traps

The Google Threat Intelligence Group (GTIG) says victims may encounter genuine authentication pages during these attacks. UNC6293 has asked targets to complete legitimate logins and surrender verification codes or URLs, while UNC5976 built fake file-sharing pages that redirected users through authentic Google OAuth screens.

After authentication, victims could be sent to attacker-controlled cloud projects designed to capture access tokens. Google says it disrupted at least 12 domains and related infrastructure created by UNC5976, which has since started shifting parts of its phishing infrastructure away from Google services.

WhatsApp linking gives attackers another route in

UNC7005, also tracked by Microsoft as Storm-2945, used fake invitations and secure-communication lures to target academics, diplomats and nonprofit personnel. In May and June, phishing pages impersonating WhatsApp asked victims to enter a phone number and approve a legitimate device-link request for an attacker-controlled device.

Once linked, the attacker could gain ongoing account access. Google also observed prompts for fake encrypted chats, file downloads and voice calls. One call flow used malicious JavaScript to record a target’s audio and video. In August, the same cluster used Google OAuth phishing against people connected to Europe’s defense industry.

Why this matters beyond high-profile targets

These operations are highly selective, but the techniques matter to everyone because they rely on familiar, legitimate-looking security workflows. A real Google sign-in page, QR code or WhatsApp linking prompt is not proof that the request leading to it is trustworthy.

Users should verify unexpected invitations through a separate channel, never share app passwords or verification codes, review linked WhatsApp devices, and treat unverified OAuth consent screens as a warning sign. Google also recommends that high-risk users consider its Advanced Protection Program.

Stay safer from phishing and account-takeover lures

Attackers increasingly build scams around legitimate services, so the initial message or link deserves as much scrutiny as the login page itself. Bitdefender Scamio can analyze suspicious messages, links and QR codes before you interact with them, while Bitdefender Ultimate Security adds anti-phishing, web, email and scam protection across supported devices.

tags


Author


Vlad CONSTANTINESCU

Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.

View all posts

You might also like

Bookmarks


loader