Overview
- Google’s Threat Intelligence Group published a consolidated warning on Friday that ties three clusters called UNC6293, UNC7005 and UNC5976 to a likely Russian nexus and details how they abuse authentication features.
- The attackers trick targets into using OAuth consent screens, creating app passwords, or approving device‑linking prompts such as WhatsApp pairing, which gives the attackers valid tokens or linked sessions that bypass normal password checks.
- UNC7005 uses device‑code phishing and fake WhatsApp pages to link attacker devices and sometimes request camera or microphone access, UNC6293 focuses on diplomatic impersonation and app‑password phishing, and UNC5976 runs automated OAuth token collection through cloud projects.
- Campaigns combine off‑the‑shelf infostealers and custom tools—examples include VIDAR, ATOMIC, ENGINELIGHT, HEADRUSH and CHERRYPIE with signs of AI‑assisted code—while attacker infrastructure is quickly rebuilt after takedowns.
- Google urges immediate steps such as revoking unknown app passwords, auditing OAuth consents and WhatsApp linked devices, enabling anti‑phishing MFA or Advanced Protection, and extending threat hunting to personal accounts and cloud project indicators to close visibility gaps.