logo

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

ID: ada99f18-d44f-510a-b97a-b2c9f93fe7b1

STIX ID: report--ada99f18-d44f-510a-b97a-b2c9f93fe7b1

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: Pierluigi Paganini

...
...

Google TAG tracked three Russia-linked espionage clusters (UNC6293, UNC7005, UNC5976) that target researchers, diplomats and defense-sector personnel by abusing legitimate authentication flows—app passwords, OAuth/device-code phishing, and WhatsApp linking—to obtain access tokens and deploy commodity and custom infostealers (VIDAR, ATOMIC, CHERRYPIE, HEADRUSH) and additional tooling; operations span conference-themed lures, captive-portal redirects at hotels, and cloud-hosted phishing infrastructure, and Google recommends revoking unknown app passwords, checking linked devices, treating unsolicited OAuth prompts as suspicious, and considering Advanced Protection for high-risk users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.