"These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms," Google Threat Intelligence Group researchers Gabby Roncone and Wesley Shields write in a report published Aug. 20, 2026.
Who GTIG says is behind the activity
Google Threat Intelligence Group (GTIG) links three suspected Russian cyber espionage clusters—UNC6293, UNC5976, and UNC7005—to a focused program of account compromise and follow‑on intrusion. UNC6293 was first detailed in June 2025 and is assessed to be a sub‑cluster of Ice Relic (also tracked as Cozy Bear and Midnight Blizzard). UNC7005, identified by GTIG in February 2026 and also tied to Ice Relic sub‑operations, and UNC5976, active since at least March 2026, each bring different technical approaches to the same strategic aim: hijacking trusted authentication flows to get into accounts belonging to academics, diplomats, defense‑related personnel, and think‑tank researchers.
UNC6293: app passwords, small‑scale lures, and OAuth follow‑ups
UNC6293 has a history of abusing legitimate authentication features. GTIG and prior reporting from the Citizen Lab described earlier campaigns that misused Google application‑specific passwords to seize accounts. Since then, UNC6293 has continued small, highly selective campaigns—typically fewer than five targets at a time—impersonating State Department officials and using diplomatic and conference‑themed lures. As recently as June 2026, GTIG observed the cluster conducting OAuth phishing that asked targets to share a verification code or full URL after a genuine login; providing that code gave the attacker access to the account.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadUNC5976: cloud‑hosted OAuth pages and the HEADRUSH plugin
GTIG says UNC5976 automated token collection by abusing cloud infrastructure. The actor bought file‑sharing style domains, created cloud projects tied to those domains, and hosted fake file‑sharing pages. After a short dwell on the page a pop‑up offered a "Continue with Google" button that redirected the user to a legitimate Google OAuth login. Following authentication, victims were sent to a Google Cloud project URL that ran scripts to extract the authentication token from the URL and stage it for later use. Google disrupted at least 12 domains and related infrastructure UNC5976 created since March 2026; the actor then pivoted to other providers.
UNC5976 has also distributed a rogue Excel plugin codenamed HEADRUSH that delivered an HTML Application (HTA). Discovered in April 2026 and hosted on a fake site impersonating a Ukrainian research institute, the HEADRUSH artifact shows indications of targeting a Ukrainian aerospace and imaging company, though GTIG says the full scope of infection is unknown. GTIG describes the group’s operational focus as centered on military, aerospace, the defense industrial base, and NGOs/think tanks, with geographic focus on Ukraine and Armenia.
UNC7005: WhatsApp device linking, CaptiveCrunch, and commodity malware
UNC7005 has run a multifaceted campaign that blends social engineering, AitM interception, and commodity infostealers. GTIG describes device‑code phishing against Microsoft and WhatsApp accounts and the reuse of diplomatic event lures (including wine‑themed prompts). In May and June 2026, UNC7005 spoofed WhatsApp pages that asked targets for a phone number, used that number to create a legitimate WhatsApp device link request with an attacker device, and displayed the real QR and linking code for the victim to approve. Once the attacker had linked a victim’s account, the phishing page presented prompts to join a voice call, encrypted chat, or download a file. Choosing the voice call caused JavaScript to record audio and video and send those recordings to a command‑and‑control (C2) endpoint; the encrypted‑chat path prompted the user to copy credentials to a secondary URL.
Beginning July 31, 2026, GTIG observed UNC7005 registering domains spoofing the Finnish Operations Center; between Aug. 6 and Aug. 13, 2026 the actor sent targeted phishing emails to European defense‑industry targets linking to attacker‑controlled domains that redirected victims to legitimate Google OAuth logins before capturing tokens in unverified cloud projects.
UNC7005’s activity dovetails with a broader operation dubbed CaptiveCrunch, documented by ReliaQuest and Microsoft late last month, that abuses captive Wi‑Fi portals in hotels, conference centers, and airports. Microsoft reports the attacker obtained administrative access to Wi‑Fi gateways, used DNS poisoning and AitM interception against Microsoft Entra ID device‑code flows, and pushed malware masquerading as browser or OS updates. Delivered payloads include a Go‑based remote access trojan called CornFlake RAT and a PowerShell infostealer called ChocoShell (aka CHERRYPIE); Microsoft notes ChocoShell was likely generated by a large language model. The operation is managed through a centralized web‑based C2 panel called FruitStone, presented as "CloudSync Console" and associated with "Acuity Systems, Inc." in an apparent attempt to appear legitimate.
What this means for academics, defense buyers, and travelers
- Academics, diplomats, and think‑tank researchers: UNC7005 and UNC6293 specifically target these groups with highly tailored lures—diplomatic invitations, summit companion apps, and topic‑specific appeals—making individuals who work on Russia, former Soviet states, defense, and policy research particular targets.
- Defense and security procurement organizations: UNC7005 registered domains spoofing the Finnish Operations Center and targeted European defense‑industry contacts between Aug. 6 and Aug. 13, 2026, showing attackers will emulate relevant institutional partners to harvest OAuth tokens.
- Travelers and conference attendees: CaptiveCrunch telemetry from Lumen Black Lotus Labs identified roughly 70 victim IP addresses linked to the campaign; about 40 of those IPs sent DNS requests to the CaptiveCrunch C2s and some communicated with AitM infrastructure, indicating travelers using hotel and airport Wi‑Fi were among the groups subjected to redirection and token harvesting.
GTIG concludes that these clusters' creative abuse of legitimate features—from app passwords to device linking—complicates efforts to distinguish legitimate from malicious access. The same techniques enable rapid exfiltration and create springboards for further phishing from compromised, genuine accounts. For defenders, the record assembled by Google, Microsoft, ReliaQuest, Lumen, and other observers crystallizes a single point: attackers are increasingly weaponizing trusted authentication flows rather than relying on simple credential theft.




