Google Identifies Three Russian Spy Groups Hijacking Auth Flows, Bypassing MFA
Google Threat Intelligence Group published research on August 20, 2026, detailing three suspected Russian espionage clusters — UNC6293, UNC7005, and UNC5976 — that exploit authentication flows rather than stealing passwords directly. The groups target academics, government officials, aerospace and defense personnel, and think tank staff across Europe, Ukraine, and the United States. Their methods include abusing OAuth consent flows, application-specific passwords, device code grants, and WhatsApp device linking, meaning fully deployed multi-factor authentication does not stop the attacks. UNC5976, active since at least March 2026, automated OAuth token harvesting using legitimate cloud infrastructure, redirecting victims through real Google login pages before silently stealing tokens post-authentication. Google disrupted at least 12 related domains, but UNC5976 adapted by migrating its phishing infrastructure to other providers and also deployed a malicious Excel plugin called HEADRUSH targeting Ukrainian organizations.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in