Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
ID: ada99f18-d44f-510a-b97a-b2c9f93fe7b1
STIX ID: report--ada99f18-d44f-510a-b97a-b2c9f93fe7b1
Feed Name: Security Affairs
Google TAG tracked three Russia-linked espionage clusters (UNC6293, UNC7005, UNC5976) that target researchers, diplomats and defense-sector personnel by abusing legitimate authentication flows—app passwords, OAuth/device-code phishing, and WhatsApp linking—to obtain access tokens and deploy commodity and custom infostealers (VIDAR, ATOMIC, CHERRYPIE, HEADRUSH) and additional tooling; operations span conference-themed lures, captive-portal redirects at hotels, and cloud-hosted phishing infrastructure, and Google recommends revoking unknown app passwords, checking linked devices, treating unsolicited OAuth prompts as suspicious, and considering Advanced Protection for high-risk users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
