Russian Spy Phish Uses Legit OAuth Logins

The Register Security · High sophistication
Last updated August 21, 2026

Google says three suspected Russian cyber-espionage groups are running highly targeted phishing campaigns against people in government, academia, defense, and think tanks in the US and Europe. A key theme is abusing legitimate Google/Microsoft OAuth login flows so the outreach looks real, tricking victims into granting account access or installing malware.

Key findings

  • Google tracks three suspected Russian groups (UNC6293, UNC7005, UNC5976) targeting individuals in academia, aerospace, defense, government agencies, and think tanks in Europe and the US.
  • The campaigns are highly targeted: “Each campaign had fewer than 100 targets, and under 10 victims.”
  • Attackers “adapted their attacks to abuse legitimate authentication flows,” including OAuth, making the lures look more legitimate and harder to recognize as phishing.
  • UNC6293 (linked to APT29/Cozy Bear) impersonates US State Department employees and has added OAuth phishing that asks victims to share a URL or “verification code.”
  • UNC7005 uses diplomatic/conference-themed lures, attacker-controlled event sites, device-code phishing for Microsoft and WhatsApp, and malware delivery disguised as conference apps.
  • UNC5976 uses fake file-sharing domains and a “Continue with Google” flow that routes victims through a real Google OAuth login, then captures tokens via a Google Cloud project redirect.

Who’s being targeted

  • Commonly targeted roles: Executives and senior leaders, Government and public sector staff, Academics and researchers, Policy/think-tank personnel, Aerospace and defense staff, Anyone who manages identity/login workflows (IT/Identity teams).
  • Affected industries: Government, Education / Academia, Aerospace and Defense, Think tanks / Nonprofits.
  • Attack channels: email, website.
  • Impersonated: US State Department employee, Diplomatic conference organizer (spoofed event/forum), File-sharing service.

Awareness takeaways

  • Treat unexpected calendar invites and government-themed outreach as suspicious until verified through known channels.
  • Never share verification codes, device codes, or post-login URLs with anyone, those can directly grant account access.
  • Be cautious of event or conference invitations that send you to external registration sites, especially if they ask you to download an app or file.
  • A real Google login page doesn’t guarantee safety, attackers can abuse OAuth to capture tokens after you authenticate.

Red flags to watch for

  • A third party asks you to share a login “verification code” or a post-login URL
  • Pressure to complete an authentication process outside official channels
  • Unexpected State Department-themed outreach tied to account access
  • Event link goes to an unexpected/non-official domain or a lookalike site
  • Registration process feels oddly detailed or manipulative (e.g., unusual extras like wine selection)
  • Downloading an app/file just to read a resolution or conference materials
  • File-sharing site pushes “Continue with Google” unexpectedly or from a newly seen domain
  • You are redirected to unfamiliar Google Cloud project URLs after login
  • Unexpected authentication prompts for accessing a file share
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You log in with real Google or Microsoft OAuth… and still hand your account to a spy. Groups like UNC6293, linked to APT29, email you as a US State Department contact. After you sign in on a real provider page, they ask you to reply with the full URL or a ‘verification code’ to finish access. Others send glossy diplomatic conference invites with links to registration sites on odd domains. You confirm attendance, then get pushed to download a 'Summit Companion App' that’s actually malware. Here’s the rule: never share verification codes, device codes, or post-login URLs with anyone. If an email asks for that, stop and report it to security immediately.

Similar attacks

Russian Clusters Abuse Login Flows to Steal Accounts

Russian Clusters Abuse Login Flows to Steal Accounts

Google says three suspected Russian espionage clusters are targeting academics, think tanks, diplomats, and related nonprofit staff by abusing legitimate login and verification workflows that may not look like “classic phishing.” The campaigns include app-password scams, OAuth/device-code tricks,…

August 20, 2026
Russian Clusters Hijack Accounts via OAuth & WhatsApp

Russian Clusters Hijack Accounts via OAuth & WhatsApp

Google says multiple suspected Russia-linked espionage clusters targeted academics, government, and defense-related personnel by abusing legitimate sign-in features instead of using obvious fake login pages. The campaigns used realistic lures (file sharing, conference invites, and “secure WhatsApp”…

August 20, 2026
Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Microsoft says Russian-linked threat actors compromised hotel and conference guest Wi‑Fi “captive portal” networks to redirect travelers to fake Microsoft 365 sign-in pages, device-code phishing, or fake update pages. The goal was to steal cloud credentials (including Entra ID device codes) and…

August 4, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker…

August 4, 2026