{"id":2470,"date":"2026-08-20T20:56:04","date_gmt":"2026-08-20T20:56:04","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2470"},"modified":"2026-08-20T20:56:04","modified_gmt":"2026-08-20T20:56:04","slug":"suspected-russian-hackers-abuse-google-oauth-and-whatsapp-linking-to-hijack-accounts","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2470","title":{"rendered":"Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEix5lAWOEf4I8fcz0CJYg-EBclOrTPnlbsf6tKT2-L8xsfQ4XqtjOq15iU6EBbIsWlqQq3e1-hIXrPe7MMg4JwSGj6mSwjSwG8V3UFMrfgYD-Lo9bKvncTGJ9lPbZoxq-1RNmKLyL_jZSiurWVgGuIxjgYYJeXW_wE51PRTDUhT7kRxp0MMpc3YflI9bntb\/s1700-e365\/google-whatsapp.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S.<\/p>\n<p>These clusters include <strong>UNC6293<\/strong>, <strong>UNC7005<\/strong>, and <strong>UNC5976<\/strong>.<\/p>\n<p>\u00abThese clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms,\u00bb Google Threat Intelligence Group (GTIG) researchers Gabby Roncone and Wesley Shields <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/distinct-clusters-target-individuals-of-interest-to-russia\" target=\"_blank\">said<\/a> in a report published today.<\/p>\n<p>UNC6293, first detailed by the tech giant and the Citizen Lab in June 2025, is assessed to be a sub-cluster of Ice Relic (formerly APT29), which is also tracked under the monikers Cozy Bear and Midnight Blizzard. The hacking crew was previously attributed to a campaign that abused a Google account feature called application specific passwords to seize control of victim accounts.<\/p>\n<p>Since then, the threat actor has continued to engage in phishing campaigns that tend to be small in scope, targeting fewer than five users at a time, while impersonating State Department officials to perform app password phishing. The application names and lures revolve around diplomatic themes and upcoming conferences or meetings, some of which were highlighted by Volexity in December 2025.<\/p>\n<p>As recently as June 2026, Google said it observed the threat actor conducting OAuth phishing by requesting targets to share either the full URL or verification code after performing a legitimate login to an external provider. Once the requested verification code is provided, it allows the attackers to access the target&#8217;s account.<\/p>\n<p>UNC5976, the second threat group with an authentication focus, has been found to use OAuth phishing techniques and automate the collection of tokens by abusing cloud infrastructure. The adversary is believed to be active since at least March 2026.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abTo perform these OAuth phishing campaigns, UNC5976 purchased domains, usually using file-sharing-related domain names, and then created a cloud project related to that domain,\u00bb GTIG said. \u00abThese domains host a fake file sharing page. After a target visits the page for a few seconds, the page displays a pop-up login dialog.\u00bb<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The pop-up features a \u00abContinue with Google\u00bb button that, if clicked, redirects the victim to the legitimate Google OAuth login page, asking them to sign in to continue. Upon successful authentication, the victim is sent to a Google Cloud project URL that hosts malicious scripts designed to retrieve the authentication token from the URL and stage it for later use.<\/p>\n<p>The threat actor is estimated to have created no less than 12 new domains and related infrastructure since March 2026, all of which have since been disrupted by Google. The actions are said to have prompted UNC5976 to pivot away from Google infrastructure to other providers to host their phishing pages.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh8k26aQE3-IFTAuHYHtD05QWrul6yWDPNTvyW9Tse4qm0bfafL6J3rkVhAnceuyb2O6tJP1ymLWVb5q8TUtLcLpVyyn5EBUmcbt4MaGlunuq6EKELolBFeHpyuI_hhsrzLJiY-f2vJ9saK_2rHfifHdvdcKLIcCePQ8darG9N8otSkmu-qtw33vqlznlGf\/s1700-e365\/1.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh8k26aQE3-IFTAuHYHtD05QWrul6yWDPNTvyW9Tse4qm0bfafL6J3rkVhAnceuyb2O6tJP1ymLWVb5q8TUtLcLpVyyn5EBUmcbt4MaGlunuq6EKELolBFeHpyuI_hhsrzLJiY-f2vJ9saK_2rHfifHdvdcKLIcCePQ8darG9N8otSkmu-qtw33vqlznlGf\/s1700-e365\/1.png\" alt=\"\" border=\"0\" data-original-height=\"896\" data-original-width=\"905\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">UNC7005 WhatsApp compromise flow<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>In addition, UNC5976 has been observed leveraging a rogue Excel plugin codenamed HEADRUSH that&#8217;s used to deliver an HTML Application (HTA) downloaded. The malware, discovered in April 2026, is distributed via a fake domain impersonating a Ukrainian research institute. There are indications that the artifact may have been used to target a Ukrainian aerospace and imaging company, although the full scope of the infection remains unknown.<\/p>\n<p>\u00abIts operational focus is primarily centered on the military, aerospace, defense industrial base, and NGOs\/think tanks,\u00bb Google said. \u00abMuch of the group&#8217;s geographic targeting has centered on Ukraine and Armenia.\u00bb<\/p>\n<h3>UNC7005 Employs Myriad Tactics<\/h3>\n<p>The threat actor that has emerged as the core focus of GTIG&#8217;s research is UNC7005 (aka Storm-2945), which it identified in February 2026 and has been found to mainly target academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the U.S.<\/p>\n<p>Both UNC6293 and UNC7005 are believed to be related to a sub-group within Ice Relic that&#8217;s focused on initial access operations, while relying on commercial residential proxies for post-compromise activity. Like UNC6293, UNC7005 has conducted highly selective app password phishing operations aimed at individuals of interest to the Kremlin.<\/p>\n<p>The hacking group has also engaged in device code phishing operations targeting both Microsoft and WhatsApp accounts, with the former making use of phishing emails containing invitations to diplomatic events and conferences. The messages embed a link to an attacker-controlled site, which profiles the site visitor and then prompts them to confirm their participation in the event and state their main course and wine preferences.<\/p>\n<p>It&#8217;s worth noting that the use of wine-related lures has been a recurring theme in Ice Relic attacks <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/apt29-evolving-diplomatic-phishing\" target=\"_blank\">dating back to April 2023<\/a>. Some aspects of the activity were codenamed SPIKEDWINE by Zscaler.<\/p>\n<p>\u00abIn May and June 2026, UNC7005 conducted social engineering operations spoofing WhatsApp,\u00bb Google said. \u00abThe phishing pages distributed by the attacker lure targets into linking their WhatsApp accounts with an attacker-controlled device in order to join a secure WhatsApp call, chat, or document share. The attacker also attempts multiple other methods of compromise after the device is linked.\u00bb<\/p>\n<p>Once the page is accessed, the target is asked to provide a phone number. The number is then used to create a legitimate WhatsApp device link request with the attacker device, after which it displays the legitimate QR and linking code to the target along with instructions to the user to link their device.<\/p>\n<p>After the target&#8217;s account is successfully linked to the attacker&#8217;s WhatsApp device, the phishing page serves an additional prompt to the user to either join a voice call, encrypted chat, or download a file. If the victim ends up joining the voice call, it triggers the execution of JavaScript to record their audio and video, and send the recording to a command-and-control (C2) endpoint.<\/p>\n<p>Should the encrypted chat option be chosen, the JavaScript prompts the target to copy the username and password presented to them to log in on a secondary URL. The exact nature of the file download remains unknown.<\/p>\n<p>Around May 2026, UNC7005 is also said to have augmented its tradecraft with commodity infostealers like Vidar and Atomic (aka AMOS) to siphon data from Windows and macOS hosts to target U.S.-based academics, diplomats, and researchers focused on Russia and former Soviet states with pushing emails containing links to malicious URLs. The URL leads to a web page spoofing a summit related to a \u00abresolution in support of Ukraine,\u00bb urging them to download a summit companion application to read the full resolution. <\/p>\n<p>\u00abIn early August 2026, UNC7005 began Google account OAuth phishing operations using cloud infrastructure,\u00bb GTIG said. \u00abBeginning on July 31, 2026, UNC7005 registered domains spoofing the legitimate Finnish Operations Center (FOC), which supports Finnish companies in the defense and security markets, specifically in the context of the North Atlantic Treaty Organization (NATO).\u00bb<\/p>\n<p>\u00abBetween August 6 and August 13, 2026, UNC7005 sent targeted phishing emails linking to an attacker-controlled domain to targets in or related to the European defense industry.\u00bb<\/p>\n<p>Users who end up navigating to the domain are redirected to a legitimate Google OAuth login page that prompts them to sign in to their account. Following successful authentication, the victims are sent to an attacker-controlled unverified cloud project to steal authentication tokens and allow the threat actor to hijack their accounts.<\/p>\n<p>These efforts also dovetail with a campaign called CaptiveCrunch, which was documented by <a href=\"https:\/\/reliaquest.com\/blog\/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality\/\" target=\"_blank\">ReliaQuest<\/a> and <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/07\/31\/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft\/\" target=\"_blank\">Microsoft<\/a> late last month. The activity specifically targets captive Wi-Fi portals in locations such as hotels, conference centers, and airports in the U.S. and elsewhere to stealthily redirect users to attacker-controlled infrastructure to steal credentials.<\/p>\n<p>The activity involves obtaining administrative access to the Wi-Fi gateways to modify devices&#8217; configurations and making use of DNS poisoning to reroute regular web traffic to dispatch connections for legitimate domains through attacker-controlled infrastructure. Per Microsoft, the traffic manipulation attacks have been ongoing since early May 2026.<\/p>\n<p>\u00abA portion of this activity leverages doppelganger domains mimicking Microsoft online services to conduct follow-on adversary-in-the-middle (AitM) phishing operations that abuse the device code authentication flow in Microsoft Entra ID,\u00bb Microsoft noted.<\/p>\n<p>Besides redirecting users through actor-controlled phishing infrastructure, the threat actor has leveraged its AitM position to distribute malware purporting to be browser or operating system updates in response to automated connectivity checks issued by the victims&#8217; browsers.<\/p>\n<p>This can either lead to the deployment of a Go-based remote access trojan called CornFlake RAT or a PowerShell payload dubbed ChocoShell (aka CHERRYPIE) that&#8217;s delivered via a ClickFix lure. The trojan is designed to conduct system enumeration, collect files and keystrokes, steal credentials and session tokens, conduct audio and video surveillance, monitor for removable media, and spawn a remote shell on infected systems.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>ChocoShell, on the other hand, is a PowerShell-based infostealer that&#8217;s used to steal browser session cookies by getting Chrome&#8217;s app-bound encryption (ABE) protections, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials from compromised systems. Evidence indicates that the malware was likely generated by a large language model (LLM).<\/p>\n<p>The entire operation is managed by means of a centralized, web-based C2 panel known as FruitStone. It&#8217;s branded as \u00abCloudSync Console\u00bb and associated with \u00abAcuity Systems, Inc.,\u00bb likely in an attempt to appear as legitimate cloud management software to escape detection.<\/p>\n<p>\u00abImplemented as a single-page application (HTML and JavaScript) serving as the front-end of the C2 server with all functionality exposed without authentication, FruitStone provides a centralized dashboard for managing compromised endpoints, building and deploying new campaign payloads, and reviewing all collected data (such as screenshots, keystrokes, browser credentials),\u00bb Microsoft said.<\/p>\n<p>The latest findings from GTIG indicate that CaptiveCrunch did not \u00abhappen in a vacuum\u00bb and that UNC7005 has been running multiple campaigns in tandem to obtain access to victim accounts.<\/p>\n<h3>CaptiveCrunch and Possible Supply Chain Attack<\/h3>\n<p>What&#8217;s more, Lumen Black Lotus Labs ongoing tracking of the same campaign has raised the possibility that the threat actor compromised several Managed Service Providers (MSPs), then abused the trust relationship with their clients in a supply chain attack.<\/p>\n<p>\u00abOnce in client networks, they could target travelers by hijacking DNS requests on a compromised WIFI router; the victims were redirected to spoofed authentication portals to harvest OAuth tokens, or the actor deployed an infostealer,\u00bb the company said in a report shared with The Hacker News.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgzAVHiBlAEWvYaPDpj8Ef1RPQ-P7xyxq5QPTCRv5HTss5ZfFxDftONRDR_bcZCbg32Q4i4Yo_rt6F8PLTLbe_9bOyKi3vqTY7egRSBKRniK47rJqdXGdMBCsATQJi3W1AOzicPOh-fxl4-jnI_2J9QdG8tsyg3WRphqWgdSxeDYEN5NIiqd__pWfSxteiH\/s1700-e365\/2.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgzAVHiBlAEWvYaPDpj8Ef1RPQ-P7xyxq5QPTCRv5HTss5ZfFxDftONRDR_bcZCbg32Q4i4Yo_rt6F8PLTLbe_9bOyKi3vqTY7egRSBKRniK47rJqdXGdMBCsATQJi3W1AOzicPOh-fxl4-jnI_2J9QdG8tsyg3WRphqWgdSxeDYEN5NIiqd__pWfSxteiH\/s1700-e365\/2.png\" alt=\"\" border=\"0\" data-original-height=\"900\" data-original-width=\"1336\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">CaptiveCrunch Likely Targets MSPs<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Telemetry data from Lumen has identified approximately 70 victim IP addresses, out of which 40 unique IPs sent DNS requests to the C2s associated with CaptiveCrunch. \u00abWe assessed that these locations indicate places where the actor had access and performed some enumeration, likely by redirecting DNS requests to their resolvers to determine whether individual travelers in these locations would be of further interest,\u00bb it added.<\/p>\n<p>Another 30 unique IP addresses have been found to communicate with the threat actor&#8217;s AitM infrastructure to harvest tokens, while a single IP address was observed interacting with the ChocoShell C2 server.<\/p>\n<p>\u00abThese clusters of Russia&#8217;s authentication-focused cyber espionage operations target multiple types of authentication using legitimate features and infrastructure, ranging from app passwords to device linking,\u00bb GTIG said. \u00abIn particular, their creative abuse of legitimate features to compromise accounts makes tracking legitimate and malicious account access more challenging.\u00bb<\/p>\n<p>\u00abThe combination of these tactics not only enables the attacker to conduct quick-turnaround exfiltration operations, but also presents opportunities for the attacker to further phish targets of interest from compromised, legitimate accounts.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2471,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[383,592,2,338,333,3106,381,54,2368,815],"class_list":["post-2470","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-abuse","tag-accounts","tag-google","tag-hackers","tag-hijack","tag-linking","tag-oauth","tag-russian","tag-suspected","tag-whatsapp"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2470","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2470"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2470\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2471"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2470"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2470"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2470"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}