Russian Clusters Hijack Accounts via OAuth & WhatsApp

The Hacker News · High sophistication
Last updated August 21, 2026

Google says multiple suspected Russia-linked espionage clusters targeted academics, government, and defense-related personnel by abusing legitimate sign-in features instead of using obvious fake login pages. The campaigns used realistic lures (file sharing, conference invites, and “secure WhatsApp” communications) to trick targets into handing over OAuth tokens or linking WhatsApp to an attacker-controlled device, enabling account takeover.

How the Attack Worked

Google identified three suspected Russia-linked espionage clusters, UNC6293, UNC7005, and UNC5976, that abused legitimate authentication flows rather than relying only on obvious fake login pages. UNC5976 registered domains resembling file-sharing services and hosted fake file-sharing pages with a "Continue with Google" button. Clicking it sent victims through the real Google OAuth login page, and scripts hosted in cloud infrastructure then stole the authentication token from the redirect URL.

UNC7005 took a different approach, spoofing WhatsApp pages that displayed a legitimate QR code and linking instructions, convincing targets to link their WhatsApp account to a device controlled by the attacker. Once linked, victims received further prompts to join a call, chat, or accept a file, extending the compromise. The same cluster also spoofed a summit site referencing a resolution in support of Ukraine, pushing victims toward a malicious companion app download.

Why It Succeeded

These campaigns worked because each step used a real, trusted service, an actual Google sign-in page, an authentic WhatsApp linking code, or a plausible event invitation. None of the individual actions looked like classic phishing. Targets were academics, diplomatic and government affairs staff, defense and aerospace personnel, and think tank employees, groups often accustomed to receiving file-sharing links, conference invitations, and secure communication requests as part of normal work.

What to Watch For

  • Unfamiliar file-sharing domains that prompt a "Continue with Google" sign-in
  • Any web page asking you to link WhatsApp or another messaging app to a new device via a scanned code
  • Event or summit invitations that require downloading a "companion app" just to view a document
  • Requests, from anyone, to share a verification code or the full URL you land on after signing in

Building Resistance

Organizations in academia, government, defense, and nonprofit sectors should train staff to treat OAuth prompts on unfamiliar sites as a red flag, even when the sign-in screen itself is genuinely Google's. Any request to link a messaging app to a new device should be verified through a separate, trusted channel before acting. Staff should also be reminded that sharing a verification code or a post-login URL with anyone, regardless of the reason given, can hand over full account access. Building this awareness helps close the gap that legitimate-looking authentication flows can otherwise exploit.

Key findings

  • Three suspected Russian espionage clusters (UNC6293, UNC7005, UNC5976) used "legitimate authentication flows" to compromise accounts rather than only relying on traditional fake login pages.
  • UNC5976 used fake file-sharing domains and a "Continue with Google" flow to send victims through real Google OAuth, then stole tokens from the redirect URL using scripts hosted in cloud infrastructure.
  • UNC7005 spoofed WhatsApp to trick victims into linking their WhatsApp account to an attacker-controlled device using a legitimate QR/linking code workflow, then pushed additional prompts (call/chat/file) for further compromise.
  • UNC7005 also spoofed a summit site about a "resolution in support of Ukraine" to push a companion app download from a malicious link.
  • Google observed OAuth phishing where targets were asked to share "the full URL or verification code" after a legitimate login, enabling attackers to access the account once shared.

Who’s being targeted

  • Commonly targeted roles: Executives, Academia / research staff, Government affairs / diplomatic teams, Defense and aerospace staff, Nonprofits / think tanks, IT helpdesk and identity/security teams.
  • Affected industries: Academia, Government, Aerospace and defense, Think tanks / nonprofits, Defense industrial base.
  • Attack channels: website, email.
  • Impersonated: File-sharing service (fake site) and Google OAuth sign-in, WhatsApp (spoofed linking page), Summit/event organizers.

Red flags to watch for

  • File-sharing site/domain doesn’t match a known provider
  • Unexpected pop-up login prompt after visiting a page
  • You are redirected to an unfamiliar cloud project URL after signing in
  • Any request to link a new device via a web page you reached from a link
  • A WhatsApp ‘secure call’ requirement that starts with entering your phone number on a non-WhatsApp site
  • Unexpected follow-up prompts to join a call/chat or download a file immediately after linking
  • Event-themed urgency pushing software installation
  • Link goes to an unfamiliar domain instead of an official event site
  • A ‘companion app’ is required just to read a document
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers steal accounts without fake login pages?

Groups like UNC5976 sent victims through the real Google OAuth login via a fake file-sharing site, then captured the authentication token from the redirect URL instead of harvesting a password directly.

What is the WhatsApp linking attack?

UNC7005 spoofed WhatsApp pages that displayed a legitimate QR or linking code, tricking targets into linking their WhatsApp account to an attacker-controlled device.

Who was targeted in these campaigns?

Academics, government affairs and diplomatic staff, defense and aerospace personnel, and nonprofit or think tank workers were among the targeted groups.

Why is sharing a verification code dangerous?

Google observed attackers asking targets to share the full post-login URL or a verification code, which alone can let attackers access the account even after a legitimate sign-in.

Read the video transcript

Imagine this: you tap a real Google login… and that’s exactly how UNC5976 walks into your account. Their fake file-sharing page sends you through real Google OAuth, then scripts grab your token from the redirect URL, no fake password box, just stolen access. Same play with WhatsApp: a spoofed ‘secure WhatsApp call’ page walks you through linking, but the QR actually connects your WhatsApp to their device, then pushes chats and file prompts. Here’s the move: any unfamiliar site asking you to 'Continue with Google' or link WhatsApp from a link, stop, close it, and open the service yourself from your own bookmark or app instead.

Similar attacks

Russian Clusters Abuse Login Flows to Steal Accounts

Russian Clusters Abuse Login Flows to Steal Accounts

Google says three suspected Russian espionage clusters are targeting academics, think tanks, diplomats, and related nonprofit staff by abusing legitimate login and verification workflows that may not look like “classic phishing.” The campaigns include app-password scams, OAuth/device-code tricks,…

August 20, 2026
Russian Spy Phish Uses Legit OAuth Logins

Russian Spy Phish Uses Legit OAuth Logins

Google says three suspected Russian cyber-espionage groups are running highly targeted phishing campaigns against people in government, academia, defense, and think tanks in the US and Europe. A key theme is abusing legitimate Google/Microsoft OAuth login flows so the outreach looks real, tricking…

August 21, 2026
Vishing “Help Desk” Scams and Lookalike Phish Surge

Vishing “Help Desk” Scams and Lookalike Phish Surge

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that…

August 14, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Cybercrime as a Service Fuels New Scam Waves

Cybercrime as a Service Fuels New Scam Waves

A threat landscape report describes how criminals now buy or rent phishing, fraud, malware, and hidden infrastructure “as a service,” making scams faster to launch and harder to stop. The article highlights practical, repeatable social-engineering workflows such as fake CAPTCHA pages that trick…

July 31, 2026