Multiple suspected Russian cyber espionage threat groups have been identified utilizing legitimate authentication methods to target individuals in academia, aerospace and defense, governments, and think tanks in Europe and the U.S.
The clusters, known as UNC6293, UNC7005, and UNC5976, are engaging in persistent phishing campaigns with sophisticated social engineering tactics to compromise personal accounts across various platforms.
UNC6293, previously linked to Ice Relic (APT29), has been conducting phishing campaigns targeting State Department officials using application specific passwords. The group has evolved to engage in OAuth phishing, requesting verification codes after legitimate logins to access targets’ accounts.
UNC5976, another threat group, has been using OAuth phishing techniques to collect tokens by setting up fake file-sharing pages on purchased domains, automating the token collection process.
UNC7005, identified as Storm-2945, primarily targets academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the U.S. The group has been involved in various operations, including device code phishing targeting Microsoft and WhatsApp accounts.
UNC7005 has also employed commodity infostealers like Vidar and Atomic to steal data from compromised systems. The group has been using various tactics, including Google account OAuth phishing and leveraging legitimate Finnish Operations Center domains to steal authentication tokens.
Additionally, UNC7005 has been running campaigns like CaptiveCrunch, targeting captive Wi-Fi portals in hotels, conference centers, and airports to redirect users to attacker-controlled infrastructure for credential theft.
Lumen Black Lotus Labs has suggested that UNC7005 may have compromised Managed Service Providers and conducted supply chain attacks to target travelers by hijacking DNS requests on compromised Wi-Fi routers.
These Russia-linked threat groups are utilizing legitimate features and infrastructure to compromise accounts, making it challenging to track their activities and distinguish between legitimate and malicious access.



