logo

Russian Hackers Use Fake Google Drive and Diplomatic Lures to Steal Online Account

ID: 049316b2-69d1-5251-a30c-38fa45ec62ab

STIX ID: report--049316b2-69d1-5251-a30c-38fa45ec62ab

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: Tushar Subhra Dutta

...
...

Russian-linked operators are running targeted OAuth and device-code phishing campaigns against academia, think tanks, government-linked bodies, and defense organizations in Europe and the U.S., using convincing Google Drive lookalikes, diplomatic-themed lures, and proxy-based AiTM techniques to capture consent tokens, device codes, app passwords, or active sessions; the report documents clusters UNC6293, UNC7005, and UNC5976, lists extensive IoCs (domains, IPs, CSS/header/hash fingerprints), and advises monitoring consent grants, session activity, and deploying phishing-resistant authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.