Alleged Russian Hackers Exploit Legitimate Login Tools to Target US and European Accounts

Kinyua Njeri (Sam Kin)  - Tech Expert
Last updated: August 22, 2026
Share
Russian Hackers Exploit Legitimate Login Tools to Target US and European Accounts
  • Cyber espionage groups in Russia (UNC6293, UNC5976, and UNC7005) are taking advantage of real authentication methods, such as Google OAuth, app passwords, and WhatsApp device linking, to compromise target accounts.
  • UNC7005 uses fake WhatsApp pairing prompts to link victim accounts, secretly record video and audio calls, and deploy infostealing malware like Vidar and Atomic Stealer.
  • The CaptiveCrunch campaign compromises public Wi-Fi gateways and Managed Service Providers to execute DNS poisoning and deploy trojans like CornFlake RAT and ChocoShell.

Suspected Russian cyber espionage groups are targeting key individuals across Europe and the United States. The attackers manipulate legitimate account authentication processes on major tech platforms to hijack sensitive user accounts.

Researchers from the Google Threat Intelligence Group recently identified three distinct threat clusters behind these operations. These malicious teams continuously update their social engineering schemes to breach targets in aerospace, defense, government, and academia.

Exploiting application passwords and OAuth workflows

The first threat actor group, tracked as UNC6293, operates as a specialized unit within the larger Russian state-sponsored cluster known as Ice Relic. Cyber analysts observe that the group runs selective phishing attempts against fewer than five victims at a time.

Additionally, the operatives spoof communications from the United States Department of State to trick victims. They urge individuals to create application-specific passwords on their accounts. The hackers then collect these passcodes to take full control of the targeted mailboxes without triggering secondary security prompts.

Lately, UNC6293 modified its strategy to execute advanced OAuth phishing schemes. The threat actors prompt users to enter external login details and paste authentication codes directly into malicious forms. Once the target submits the verification code, the attackers harvest the token to secure permanent access.

Another distinct cluster, designated as UNC5976, focuses on automating token theft through cloud infrastructure. Active since at least March, the group registers domain names that mimic legitimate file-sharing services. The attackers establish related cloud projects connected to these domains. After spending a few seconds on the phony website, the user receives a pop-up window that requests for their log in credentials.

Consequently, clicking on the notification takes the user to an official Google OAuth login page. After successful authentication, the platform forwards the user to a malicious cloud project. Custom scripts then extract the valid security token automatically. Google recently disrupted over 12 domains associated with UNC5976. Subsequently, the group shifted its phishing scripts to alternative cloud providers.

A similar OAuth abuse pattern was observed in a GitHub incident where attackers used stolen tokens to access private repositories. In 2025, GitHub disclosed that stolen OAuth user tokens issued to third-party integrators Heroku and Travis-CI were used to download data from dozens of organizations, and researchers later linked a separate attack involving nearly 700 companies to OAuth token abuse.

Furthermore, UNC5976 uses a fake Microsoft Excel plugin named HEADRUSH to infect systems. This malicious add-in drops an HTML Application downloader disguised as documentation from a Ukrainian research facility. Investigators noted that this campaign specifically targets defense firms and military entities in Ukraine and Armenia.

Fraudulent WhatsApp device pairing and infostealers

The core focus of recent security research centers on a third active group known as UNC7005. Identified early this year, this threat team targets diplomatic personnel, academic researchers, and non-profit organizations. The group uses specialized device code phishing alongside decoy invitations to international summits. The phishing emails send targets to landing pages that collect system information before presenting tailored survey forms.

By mid-year, UNC7005 started running deceptive campaigns that impersonate the WhatsApp messaging service. The malicious web pages instruct victims to connect their mobile WhatsApp account to an external computer. The site claims this step is necessary to join a confidential call, encrypted chat, or document portal. The fake page requests the user’s phone number and generates a real device pairing request through WhatsApp. It displays the authentic QR code and numerical pairing prompt on the screen.

As soon as the target completes the pairing process, the attackers gain access to the account. The phishing interface then prompts the user to enter a video or audio call. If the victim agrees, embedded scripts secretly record the audio and video streams. The scripts transmit the recorded files directly to a command-and-control server.

In addition to account hijacking, UNC7005 deploys commodity information-stealing malware. The group uses Vidar to infect Windows computers and Atomic Stealer to compromise macOS machines. These malicious programs harvest stored web credentials, browser cookies, and local files.

In late July this year, UNC7005 registered domains imitating the Finnish Operations Center. The attackers sent targeted emails to European defense industry workers. Navigating to the links leads users to an unverified cloud project that captures OAuth authorization tokens.

Captive portal interception and supply chain attacks

The activities of UNC7005 were linked with a major Wi-Fi malware campaign referred to as CaptiveCrunch. The campaign began its work in May this year, and specializes in victimizing captive portals present in locations like airports and hotels. Thus, it allows the hackers to acquire administrative access to public Wi-Fi facilities. They alter network configurations and perform Domain Name System poisoning.

This network manipulation reroutes normal internet traffic through malicious servers. When travelers attempt to log in to online services, the poisoned network redirects them to fake login portals. These fake interfaces mimic Microsoft Entra ID device login screens to steal credentials.

Moreover, the attackers abuse this position to deliver secondary payloads. They send fake system update pop-ups when victim browsers attempt automated background checks. These prompts deliver a Go-based backdoor called CornFlake RAT or a PowerShell infostealer named ChocoShell.

ChocoShell bypasses specialized encryption safeguards inside Google Chrome to steal stored session cookies and corporate single sign-on tokens. Security analysts suspect the code for ChocoShell was generated using artificial intelligence models. The entire infrastructure reports back to a centralized control panel called FruitStone. The dashboard uses fake corporate branding to look like a standard administrative panel.

Telecommunication researchers at Lumen Black Lotus Labs suggest the hackers compromised Managed Service Providers to carry out these operations. Having compromised the providers of the services, the group gained access to manage public Wi-Fi routers remotely. Also, network telemetry shows dozens of unique internet addresses interacting with the malicious infrastructure.

Cybersecurity agencies emphasize that abusing legitimate features makes detection difficult. This means organizations must monitor connected devices and revoke unnecessary application permissions to remain protected.

Share this article

About the Author

Kinyua Njeri is a journalist, blogger, and freelance writer. He’s a technology geek but mainly an internet privacy and freedom advocate. He has an unquenchable nose for news and loves sharing useful information with his readers. When not writing, Kinyua plays and coaches handball. He loves his pets!

More from Kinyua Njeri (Sam Kin)

Comments

No comments.