logo

Russia-Linked Cyber Espionage Clusters Use OAuth Phishing to Target U.S. and European Organizations

ID: e364c128-4e87-5f26-976e-67bf28623339

STIX ID: report--e364c128-4e87-5f26-976e-67bf28623339

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: Varshini

...
...

Google Threat Intelligence Group details Russia-linked espionage clusters (UNC6293, UNC7005, UNC5976) using OAuth phishing, device-code phishing, spoofed websites, and Cloudflare-fronted infrastructure to impersonate trusted organizations and harvest access to email, cloud, and messaging accounts; researchers identified multiple domains, IPs, registration overlaps, and evidence consistent with Evilginx-style phishing and targeted lures against academia and think tanks in the United States and Europe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.