Suspected Russian Threat Clusters Abuse Google OAuth and WhatsApp Device Linking to Hijack Accounts
Google's Threat Intelligence Group has reported on three suspected Russian cyber espionage clusters — tracked as UNC6293, UNC7005, and UNC5976 — abusing legitimate authentication flows, including Google OAuth and WhatsApp device-linking mechanisms, to hijack accounts belonging to targeted individuals.
What was reported
According to Google's reporting, these clusters have been observed engaging in persistent, adaptive social engineering campaigns that single out individuals in academia, aerospace and defense, government, and think tanks across Europe, as well as academia and think tanks within the U.S. Rather than exploiting a software vulnerability, the activity leverages abuse of legitimate authentication and device-pairing flows to gain access to victim accounts. Full technical detail on each cluster's specific tradecraft was not included in the excerpt available at publication time.
Why it matters for defenders
Abuse of legitimate OAuth consent screens and messaging-app device linking is difficult to distinguish from normal user activity at the network layer, since it doesn't rely on malware or exploited software. Because the targeting is aimed at academia, aerospace/defense, government, and think tank personnel — populations often handling sensitive research, policy, or export-controlled information — successful account hijacks could translate into meaningful espionage outcomes: access to email, contacts, and any services tied to the compromised identity. Individuals who present a high-value target profile (researchers, policy staff, defense-adjacent personnel) should treat this as an active, near-term risk to personal and organizational accounts.
What defenders should watch for or do now
- Review Google Workspace/Cloud audit logs for anomalous OAuth consent grants, especially third-party app authorizations approved by high-risk users (academia, defense, government, think tank staff).
- Monitor for unusual WhatsApp "linked device" additions and educate at-risk users to periodically check and prune their linked devices list.
- Reinforce security awareness training that specifically covers OAuth consent phishing and device-linking social engineering, since these techniques rely on the victim approving a legitimate-looking prompt rather than clicking a malicious link.
- Enforce phishing-resistant MFA (e.g., FIDO2/passkeys) where possible, and restrict or tightly govern which third-party OAuth applications users are permitted to authorize.
- Encourage account-level alerting for new sign-ins, new device linkages, and new app authorizations for individuals in the targeted demographics.
Developing intelligence
This is early-stage reporting on suspected (not confirmed) Russian threat activity, and technical indicators, full cluster tradecraft, and victim scope may evolve as more detail emerges. There is no associated CVE for this campaign — it centers on abuse of legitimate authentication flows rather than a software vulnerability. For the full report, see the original coverage at The Hacker News.