Google’s Threat Intelligence Group says three suspected Russian cyber-espionage groups are targeting people in academia, aerospace, defense, government, and think tanks across Europe and the United States. The glamorous innovation this time is not a zero-day with a velvet cape. It is asking important people to approve access through legitimate authentication flows until the door opens politely.
As reported by The Register, Google is tracking the activity under three UNC clusters, including UNC6293, UNC7005, and UNC5976. Some phishing and OAuth-abuse operations took place this month, with campaigns dating back at least to last year. Google told The Register that each campaign involved fewer than 100 targets and fewer than 10 victims.
🤚 The Open-Palm State Department Invitation
The main theme is targeted social engineering with just enough official perfume to pass through a busy professional’s threat model. One lure impersonated US State Department personnel. Another abused OAuth-style authorization flows, where a target performs what looks like a legitimate login and then shares a verification code or URL that grants the attackers account access.
That is the sinister elegance of OAuth abuse. The victim is not necessarily typing a password into a fake login page with a suspicious domain and the graphic design instincts of a counterfeit vape shop. Instead, the target may interact with a real provider and a familiar consent flow, then hand over the one item the attacker needs to obtain durable access. The ceremony looks legitimate because parts of it are.
Google said it wants to raise awareness so likely targets can recognize malicious outreach. Translation: if an unexpected diplomatic meeting invite asks you to complete an authentication ritual, the correct response is not “how efficient,” but “why does this calendar item smell faintly of counterintelligence?”
👐 The Two-Handed Authentication Mirage
UNC6293 is suspected by Google of being tied to APT29, also known as Cozy Bear, a group widely linked by Western governments and security firms to Russia’s Foreign Intelligence Service. APT29 is best known to the general public for the 2020 SolarWinds operation, because every luxury espionage brand needs a signature fragrance.
Google also said UNC7005 appears, with moderate confidence, to be another initial-access group connected to the same broader Russian intelligence ecosystem. The Register notes that Microsoft tracks UNC6293 as Storm-2945, and that previous reporting from Microsoft and ReliaQuest warned of campaigns compromising captive portal networks to deliver malware through public Wi-Fi environments such as hotels and conference centers.
The operational pattern is revealing. These are not mass spam campaigns flung at humanity with the grace of a leaf blower. They are narrow, patient, and context-rich. The attackers want people whose inboxes, files, and relationships contain policy, defense, diplomatic, and research value. Fewer than ten victims can still represent a catastrophic harvest if those victims are the right people.
🌿 The Gentle Awakening
The security lesson is not “never use OAuth.” OAuth is fundamental infrastructure for modern identity and application access. The lesson is that legitimacy can be weaponized. Attackers have learned that the finest phishing page is sometimes no phishing page at all; it is a legitimate workflow nudged into an illegitimate outcome.
Organizations should treat unexpected consent prompts, verification-code requests, device-code flows, and calendar-driven login rituals as high-risk moments, especially for staff involved in diplomacy, policy, defense research, sanctions, aerospace, Ukraine-related work, or Russia analysis. Conditional access policies, app-consent restrictions, phishing-resistant multifactor authentication, device compliance checks, and user training around OAuth consent are not decorative compliance orchids. They are the reinforced hinges on the boardroom door.
Individuals should be similarly rude to convenience. Verify meeting requests through a second channel. Do not share verification codes. Do not paste authentication URLs into chats because someone with a plausible title asked warmly. If an invite arrives from a grand institution and immediately wants account authorization, assume the institution may have been rented by an adversary for the afternoon.
👑 The Gold-Leaf Reckoning
Modern espionage increasingly looks less like a hacker in a hoodie and more like a concierge with excellent timing. The attacker does not always break the window. Sometimes he books a conference room, sends an agenda, and lets the victim open the identity system from the inside.
This is why identity security has become the new perimeter, the new help desk, and the new aristocratic anxiety. Passwords, tokens, consent screens, browser sessions, and app authorizations are now diplomatic baggage. Treat them with the paranoia formerly reserved for diplomatic pouches and hotel minibar charges.
“Do not click the meeting invite merely because it has manners.” — The Slap of Wisdom Counterintelligence Etiquette Desk, declining canapés from an OAuth consent screen