logo

Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts

ID: 54b19681-a1e3-5f08-a34f-31a032fc6ff3

STIX ID: report--54b19681-a1e3-5f08-a34f-31a032fc6ff3

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: Mayura Kathir

...
...

GTIG and Validin tracking indicates Russian-linked operators (assessed UNC6293 with links to ICE RELIC/APT29) are conducting targeted account-compromise campaigns that combine OAuth-consent abuse, Evilginx-style reverse-proxy phishing, device-code phishing, and credential-harvesting decoy sites to bypass MFA and capture tokens. The report documents lure domains, shared registration artifacts, observed redirects to legitimate government sites, IP pivots, and several IOCs, and recommends behavioral detections (unfamiliar OAuth apps, anomalous device-linking, unusual token use) rather than blunt domain blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.