Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia
Suspected Russian clusters abuse OAuth and authentication flows to phish academia, defense, government, and think tank targets across Europe and the US.
Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage clusters abusing legitimate authentication flows. Newly detailed clusters UNC7005 and UNC5976 conduct phishing, abuse OAuth flows, and/or deploy malware, alongside previously reported UNC6293 phishing operations. Targets include individuals in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks in the United States.