news.mlab.sh
Back to the feed
threat-intel

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

High
Image: The Hacker News
Summary

Three distinct clusters of suspected Russian cyber espionage groups – UNC6293, UNC7005, and UNC5976 – are leveraging legitimate authentication flows to target individuals in academia, aerospace/defense, governments, and think tanks across Europe and the U.S. These groups, linked to Ice Relic (Cozy Bear/Midnight Blizzard), employ sophisticated phishing tactics, including app password abuse, device code phishing, and exploiting captive Wi-Fi networks to steal credentials and deploy malware like CornFlake RAT and ChocoShell. Recent analysis suggests a potential supply chain attack, where threat actors compromised Managed Service Providers (MSPs) to target travelers and gain access to victim networks.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.