Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
ID: 54b19681-a1e3-5f08-a34f-31a032fc6ff3
STIX ID: report--54b19681-a1e3-5f08-a34f-31a032fc6ff3
Feed Name: GBHackers
GTIG and Validin tracking indicates Russian-linked operators (assessed UNC6293 with links to ICE RELIC/APT29) are conducting targeted account-compromise campaigns that combine OAuth-consent abuse, Evilginx-style reverse-proxy phishing, device-code phishing, and credential-harvesting decoy sites to bypass MFA and capture tokens. The report documents lure domains, shared registration artifacts, observed redirects to legitimate government sites, IP pivots, and several IOCs, and recommends behavioral detections (unfamiliar OAuth apps, anomalous device-linking, unusual token use) rather than blunt domain blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
