Google’s Threat Intelligence Group says three separate Russia-linked espionage clusters, tracked as UNC6293, UNC7005, and UNC5976, are compromising diplomats, academics, and defense-industry personnel across Europe, Ukraine, and the United States not by exploiting software flaws but by abusing the authentication features those targets already trust. UNC7005 lures victims into linking their WhatsApp account to an attacker-controlled device, then uses the phone’s own camera and microphone through legitimate call functions to record audio and video. The same cluster also runs fake conference-registration pages, complete with browser fingerprinting scripts designed to detect automated security analysis, that funnel targets into Microsoft device-code phishing. UNC5976 takes a different route, spoofing file-sharing sites with “Continue with Google” buttons that route through a real Google OAuth consent screen before landing in an attacker-controlled cloud project that harvests the resulting token.

For CISOs, the significance is that none of this trips a vulnerability scanner. OAuth consent, device-code sign-in, and WhatsApp’s own linking feature are all working exactly as designed; the attack lives entirely in social engineering layered on top of legitimate flows, the same territory this publication has tracked in other state-linked campaigns like the Google Sheets command-and-control cluster targeting South Asian infrastructure.

The original insight here is in what differs between the three clusters rather than what they share: UNC5976 has already built more than a dozen new domains in the three months since its infrastructure was first disrupted and is migrating off Google Cloud to non-Google providers, a faster reconstitution cycle than most nation-state clusters this publication has covered, including the recently reindicted Mabna Institute operators. Google recommends restricting two-step verification to security keys and disabling unverified OAuth consent screens organization-wide, since both app passwords and testing-mode OAuth apps are the specific mechanisms these clusters depend on.

Source: Google Cloud Blog (Threat Intelligence Group)