Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

Russia-Linked Hackers Weaponize OAuth and WhatsApp Logins in New Espionage Campaign

What Happened

Google’s Threat Intelligence Group is tracking three suspected Russian cyber espionage clusters, designated UNC6293, UNC7005, and UNC5976, running phishing campaigns built around legitimate account authentication features rather than fake login pages. The operators manipulate targets into completing real app-password, OAuth, device-code, and WhatsApp device-linking flows, handing attackers authenticated account access despite multi-factor authentication protections already in place. UNC6293 impersonates US State Department officials to reach prominent critics of Russia, UNC7005 spoofs NATO-linked defense conferences including GLOBSEC and Finland’s Operations Center, and UNC5976 targets Ukrainian and Armenian military, aerospace, and think-tank organizations using a rogue Excel plugin to deliver malicious payloads.

Why This Matters for Canadian Organizations

Canada’s NATO membership, its defense and aerospace sector, and universities researching topics tied to Russian foreign policy place Canadian individuals and institutions within the demonstrated targeting scope of these clusters. The technique defeats one of the strongest defenses security teams recommend, multi-factor authentication, by exploiting user trust in familiar login prompts rather than attacking the underlying cryptography behind it. Federal government departments, defense contractors, and academic institutions handling research tied to NATO or Ukraine face the clearest exposure, and the Canadian Centre for Cyber Security has previously flagged Russian state-linked actors as a persistent threat to government and critical infrastructure networks under Bill C-26.

What to Do

Security teams should train users to treat unexpected app-password, device-code, and account-linking prompts with the same suspicion given to credential phishing links, since approving a legitimate-looking flow at the wrong moment hands over account access directly. Organizations should review conditional access policies for anomalous OAuth grants and device registrations, and academic and defense-adjacent institutions should brief researchers and staff with public profiles on the specific impersonation patterns Google documented. Full technical detail is available from Google Threat Analysis Group and The Hacker News.

Enjoy this article? Don’t forget to share.