← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Google Threat Intelligence Group Identifies Three Russian Cyber Espionage Clusters Abusing Authentication Flows

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • GTIG tracks three Russian cyber espionage clusters: UNC6293, UNC7005, UNC5976.
  • Targets include individuals in academia, aerospace, defense, government, and think tanks.
  • Clusters abuse legitimate authentication flows, including app passwords and OAuth.
  • UNC6293 is assessed as a sub-cluster of ICE RELIC (APT29).

Identification of Russian Cyber Espionage Clusters

The Google Threat Intelligence Group (GTIG) has reported on three distinct suspected Russian cyber espionage clusters: UNC6293, UNC7005, and UNC5976. These groups are actively targeting individuals working in sensitive sectors such as academia, aerospace and defense, governments, and think tanks in Europe and the United States. The primary method of attack involves abusing legitimate authentication flows to gain unauthorized access to accounts.

Tactics and Techniques

These clusters engage in persistent and adaptive phishing campaigns, utilizing sophisticated social engineering tactics. Their techniques include tricking users into setting specific app passwords, which attackers then use to bypass two-factor authentication, and abusing OAuth flows. UNC7005 has also been linked to hospitality captive portal redirects. The abuse of legitimate authentication processes makes these attacks particularly insidious, as they may not immediately appear as phishing attempts to users.

UNC6293 and its Operations

GTIG assesses with moderate confidence that UNC6293 is a sub-cluster of ICE RELIC, formerly known as APT29, and is responsible for initial access operations. UNC6293 was previously reported for an aggressive app password phishing campaign against prominent individuals critical of Russia. In these campaigns, attackers impersonated entities like the US State Department, providing instructions to targets on how to set app passwords that the attackers could then exploit.

Impact and Awareness

The continued use of these methods highlights a focus on compromising accounts through trusted authentication mechanisms. GTIG is raising awareness about these social engineering campaigns to help targeted individuals recognize and defend against malicious outreach. The nature of these attacks, which leverage legitimate system functionalities, poses a challenge for user detection and requires heightened vigilance.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~17 min · 15 stories · Aug 20

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Google Threat Intelligence Group (GTIG) has identified three distinct suspected Russian cyber espionage clusters, UNC6293, UNC7005, and UNC5976, that are abusing legitimate authentication flows to target individuals in academia, aerospace, defense, government, and think tanks across Europe and the United States. These groups employ persistent phishing and social engineering tactics to compromise accounts, often by tricking users into setting app passwords or abusing OAuth flows. This matters because these techniques exploit trusted authentication processes, making them harder for targets to recognize as malicious and posing a significant threat to sensitive information.