logo

Russian snoops add OAuth abuse to targeted phishing campaigns

ID: 76215db2-921e-5110-8e61-06f0b00b258a

STIX ID: report--76215db2-921e-5110-8e61-06f0b00b258a

Feed Name: The Register (Security)

Threat Score
82/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

...
...

Google's Threat Intelligence Group reports three suspected Russian cyber-espionage clusters (UNC6293, UNC7005, UNC5976) conducting ongoing, highly targeted campaigns against academia, aerospace, government, NGOs and think tanks in Europe and the US; their methods include OAuth and device-code phishing, malicious JavaScript and hosting attacker-controlled sites that deliver infostealers, keyloggers and other malware, with under 100 targets per campaign but high strategic impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.