Image: storage.googleapis.com · rights & removal
Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia
Reporting by Google Cloud Threat IntelligenceRead the original at cloud.google.com
Executive Summary
The Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters that leverage legitimate authentication flows to target individuals in academia, aerospace, defense, governments, and think tanks across Europe and the United States. These clusters include UNC6293, UNC7005, and UNC5976, which engage in phishing, abuse OAuth flows, and deploy malware. The operations focus on persistent, adaptive social engineering to compromise accounts through methods like app password phishing, device code phishing, and OAuth manipulation.
UNC6293 is assessed as a sub-cluster of ICE RELIC responsible for initial access, involving app password phishing impersonating the U.S. State Department and later incorporating OAuth phishing by requesting verification codes. UNC7005 targets personnel across various regions with lower operational security, employing app password phishing, device code phishing for Microsoft and WhatsApp accounts, and a broader malware deployment capability utilizing Malware-as-a-Service (MaaS) and Large Language Models (LLMs). UNC7005 also utilized infrastructure mimicking Microsoft authentication resources via hospitality captive portals.
UNC5976 is distinct, focusing on OAuth phishing and automation of token collection using cloud infrastructure, often involving the creation of fake file-sharing pages to steal Google OAuth tokens. This cluster also deployed malware like HEADRUSH to distribute infostealer tools, and has shown a migration away from Google infrastructure. The threat actors demonstrate significant overlap with historical ICE RELIC operations but exhibit distinct operational focuses and toolsets.
Facts Only
* Google Threat Intelligence Group (GTIG) is tracking three suspected Russian cyber espionage threat clusters: UNC6293, UNC7005, and UNC5976.
* UNC6293 operations involve app password phishing impersonating the U.S. State Department, sometimes requesting app passwords via external websites.
* UNC6293 later incorporated OAuth phishing by requesting verification codes after a legitimate login to an external provider.
* UNC7005 targets academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the US.
* UNC7005 conducts app password phishing using unique passwords tied to social engineering themes.
* UNC7005 performs device code phishing for Microsoft and WhatsApp accounts, often involving landing pages that request user confirmation or registration (e.g., a GLOBSEC-themed registration form).
* UNC7005 used malicious JavaScript to record audio and video during WhatsApp linking operations and upload recordings to a C2 endpoint.
* UNC7005 utilized Malware-as-a-Service (MaaS) and infostealers, such as VIDAR for Windows and ATOMIC for macOS, delivered via phishing links to target system information.
* UNC7005 performed Google account OAuth phishing by registering domains spoofing the Finnish Operations Center (FOC) to steal authentication tokens.
* UNC7005 infrastructure mimicking Microsoft authentication resources was linked to hospitality captive portal redirects observed by Reliaquest and Microsoft.
* UNC5976 focused on OAuth phishing and automation of token collection via abuse of cloud infrastructure, using fake file-sharing pages to obtain Google OAuth tokens.
* UNC5976 distributed the HEADRUSH malware, which led to an HTML Application (HTA) downloader.
* UNC7005 and UNC6293 share operational methodologies related to ICE RELIC initial access operations, including targeting shared industry sectors and using residential proxies.
Full Take
The observed progression across the threat clusters reveals an evolution in adversary sophistication, moving from targeted credential theft via app passwords (UNC6293) to broader, more integrated exploitation of authentication protocols like OAuth (UNC5976) and device linking mechanisms (UNC7005). The shared thread connecting these activities is the systematic abuse of trust inherent in legitimate identity and authentication workflows. UNC6293 and UNC7005 demonstrate a foundational relationship as sub-clusters potentially stemming from ICE RELIC, indicating a lineage rooted in specific patterns of initial access targeting high-value personnel in defense and academia. This linkage suggests an intentional strategy to exploit established, trusted channels for entry into sensitive environments.
The incorporation of MaaS and LLMs by UNC7005 introduces a dimension of operational agility, allowing actors to rapidly deploy bespoke tooling and adapt their methods with less time spent on staging infrastructure. This operational shift creates a significant challenge for defense, as the reliance on legitimate flows obscures malicious activity, making standard perimeter defenses less effective against these credential-based attacks. Furthermore, UNC5976's migration away from direct infrastructure towards cloud-based token collection signals an adaptation to evolving defensive measures, indicating a strategic response to disruption by threat intelligence providers.
The persistent use of legacy themes, such as diplomatic references, in conjunction with modern technical exploits suggests that the motivation is tied to long-term intelligence gathering on specific sectors rather than purely opportunistic financial gain. The fact that these groups leverage infrastructure across disparate contexts—from hospitality captive portals to cloud projects—demonstrates a cohesive, adaptive strategy aimed at maintaining visibility gaps, which ultimately forces security teams to focus remediation efforts on endpoint hardening and behavioral analysis rather than just blocking known malicious IPs. What are the systemic vulnerabilities in trusting authentication mechanisms when state actors prioritize anonymity and adaptation? How can organizations build defenses that assume compromise of legitimate processes is inevitable?
From the original · Google Cloud Threat Intelligence
Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most.Read the full story at cloud.google.com
Sentinel — Human
This analysis appears to be highly detailed threat intelligence written by subject matter experts, featuring specific operational timelines and deep technical artifacts, suggesting a high degree of human authorship or direct curation from specialized sources.
