The Google Threat Intelligence Group (GTIG) has reported on three distinct suspected Russian cyber espionage clusters: UNC6293, UNC7005, and UNC5976. These groups are actively targeting individuals working in sensitive sectors such as academia, aerospace and defense, governments, and think tanks in Europe and the United States. The primary method of attack involves abusing legitimate authentication flows to gain unauthorized access to accounts.
These clusters engage in persistent and adaptive phishing campaigns, utilizing sophisticated social engineering tactics. Their techniques include tricking users into setting specific app passwords, which attackers then use to bypass two-factor authentication, and abusing OAuth flows. UNC7005 has also been linked to hospitality captive portal redirects. The abuse of legitimate authentication processes makes these attacks particularly insidious, as they may not immediately appear as phishing attempts to users.
GTIG assesses with moderate confidence that UNC6293 is a sub-cluster of ICE RELIC, formerly known as APT29, and is responsible for initial access operations. UNC6293 was previously reported for an aggressive app password phishing campaign against prominent individuals critical of Russia. In these campaigns, attackers impersonated entities like the US State Department, providing instructions to targets on how to set app passwords that the attackers could then exploit.
The continued use of these methods highlights a focus on compromising accounts through trusted authentication mechanisms. GTIG is raising awareness about these social engineering campaigns to help targeted individuals recognize and defend against malicious outreach. The nature of these attacks, which leverage legitimate system functionalities, poses a challenge for user detection and requires heightened vigilance.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Google Threat Intelligence Group (GTIG) has identified three distinct suspected Russian cyber espionage clusters, UNC6293, UNC7005, and UNC5976, that are abusing legitimate authentication flows to target individuals in academia, aerospace, defense, government, and think tanks across Europe and the United States. These groups employ persistent phishing and social engineering tactics to compromise accounts, often by tricking users into setting app passwords or abusing OAuth flows. This matters because these techniques exploit trusted authentication processes, making them harder for targets to recognize as malicious and posing a significant threat to sensitive information.