AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 24 Aug, 12:14

Google says three suspected Russia-linked hacking clusters are stealing accounts through real Google and Microsoft login pages to target government, defense and academic targets in Europe and the US

Google's Threat Intelligence Group says three suspected Russia-linked hacking clusters, tracked as UNC6293, UNC7005 and UNC5976, are abusing legitimate OAuth and account-linking login flows to steal access from people in government, defense and academic institutions across Europe and the US, per Google Cloud Blog and The Hacker News.

Google's Threat Intelligence Group (GTIG) says three suspected Russia-linked cyber espionage clusters, tracked as UNC6293, UNC7005 and UNC5976, are abusing legitimate authentication features such as OAuth logins, application-specific passwords and WhatsApp device linking, rather than traditional malware, to hijack accounts. Targets include people in academia, aerospace and defense, government and think tanks across Europe, plus academia and think tanks in the US. UNC7005 registered domains impersonating Finland's Operations Center, a real organization that supports Finnish defense and security companies in a NATO context, starting July 31, 2026, then sent targeted phishing emails to people in or connected to the European defense industry between August 6 and 13, 2026. UNC5976 has registered at least 12 new phishing domains since March 2026 to automate the theft of OAuth login tokens. Google describes all three clusters as 'suspected' Russia-linked and has not published definitive attribution. Google $GOOGL and Microsoft $MSFT authentication systems were abused via legitimate login flows; neither company's systems were themselves compromised. Sources: Google Cloud Blog / Google Threat Intelligence Group report (Aug 20, 2026), The Hacker News.

#cyber
Published on