Russian snoops add OAuth abuse to targeted phishing campaigns
ID: 76215db2-921e-5110-8e61-06f0b00b258a
STIX ID: report--76215db2-921e-5110-8e61-06f0b00b258a
Feed Name: The Register (Security)
Google's Threat Intelligence Group reports three suspected Russian cyber-espionage clusters (UNC6293, UNC7005, UNC5976) conducting ongoing, highly targeted campaigns against academia, aerospace, government, NGOs and think tanks in Europe and the US; their methods include OAuth and device-code phishing, malicious JavaScript and hosting attacker-controlled sites that deliver infostealers, keyloggers and other malware, with under 100 targets per campaign but high strategic impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
