news.mlab.sh
Back to the feed
threat-intel

Russian snoops add OAuth abuse to targeted phishing campaigns

High
Image: The Register
Summary

Google has identified three distinct groups of Russian cyber-spies – UNC6293, UNC7005, and UNC5976 – that are aggressively targeting individuals in academia, defense, government, and think tanks across Europe and the US. These groups are utilizing sophisticated phishing tactics, including OAuth abuse and device-code phishing, to gain long-term access to accounts and deploy malware, often impersonating organizations like the US State Department. The threat is particularly concerning due to the groups' use of AI-assisted operations and their ability to blend in with legitimate communications.

Read the full article at The Register

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.