Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three distinct clusters of suspected Russian cyber espionage groups – UNC6293, UNC7005, and UNC5976 – are leveraging legitimate authentication flows to target individuals in academia, aerospace/defense, governments, and think tanks across Europe and the U.S. These groups, linked to Ice Relic (Cozy Bear/Midnight Blizzard), employ sophisticated phishing tactics, including app password abuse, device code phishing, and exploiting captive Wi-Fi networks to steal credentials and deploy malware like CornFlake RAT and ChocoShell. Recent analysis suggests a potential supply chain attack, where threat actors compromised Managed Service Providers (MSPs) to target travelers and gain access to victim networks.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
