Russian Hackers Use Fake Google Drive and Diplomatic Lures to Steal Online Account
ID: 049316b2-69d1-5251-a30c-38fa45ec62ab
STIX ID: report--049316b2-69d1-5251-a30c-38fa45ec62ab
Feed Name: cybersecurityNews.com
Russian-linked operators are running targeted OAuth and device-code phishing campaigns against academia, think tanks, government-linked bodies, and defense organizations in Europe and the U.S., using convincing Google Drive lookalikes, diplomatic-themed lures, and proxy-based AiTM techniques to capture consent tokens, device codes, app passwords, or active sessions; the report documents clusters UNC6293, UNC7005, and UNC5976, lists extensive IoCs (domains, IPs, CSS/header/hash fingerprints), and advises monitoring consent grants, session activity, and deploying phishing-resistant authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
