
Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features to compromise personal accounts of people in sensitive sectors across Europe and the US, Google says.
The Google Threat Intelligence Group (GTIG) says victims may encounter genuine authentication pages during these attacks. UNC6293 has asked targets to complete legitimate logins and surrender verification codes or URLs, while UNC5976 built fake file-sharing pages that redirected users through authentic Google OAuth screens.
After authentication, victims could be sent to attacker-controlled cloud projects designed to capture access tokens. Google says it disrupted at least 12 domains and related infrastructure created by UNC5976, which has since started shifting parts of its phishing infrastructure away from Google services.
UNC7005, also tracked by Microsoft as Storm-2945, used fake invitations and secure-communication lures to target academics, diplomats and nonprofit personnel. In May and June, phishing pages impersonating WhatsApp asked victims to enter a phone number and approve a legitimate device-link request for an attacker-controlled device.
Once linked, the attacker could gain ongoing account access. Google also observed prompts for fake encrypted chats, file downloads and voice calls. One call flow used malicious JavaScript to record a target’s audio and video. In August, the same cluster used Google OAuth phishing against people connected to Europe’s defense industry.
These operations are highly selective, but the techniques matter to everyone because they rely on familiar, legitimate-looking security workflows. A real Google sign-in page, QR code or WhatsApp linking prompt is not proof that the request leading to it is trustworthy.
Users should verify unexpected invitations through a separate channel, never share app passwords or verification codes, review linked WhatsApp devices, and treat unverified OAuth consent screens as a warning sign. Google also recommends that high-risk users consider its Advanced Protection Program.
Attackers increasingly build scams around legitimate services, so the initial message or link deserves as much scrutiny as the login page itself. Bitdefender Scamio can analyze suspicious messages, links and QR codes before you interact with them, while Bitdefender Ultimate Security adds anti-phishing, web, email and scam protection across supported devices.
tags
Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.
View all posts