ELSEIF
Your brief EB
367 stories from 119 feeds 464 clusters Refreshed 5 minutes ago next pull 08:38

SECURITY Signal 364

Russian cyber-spy groups reportedly abuse OAuth flows in targeted phishing campaigns against aerospace and government sectors

Suspected Russian threat groups are using OAuth phishing to gain persistent access to email and cloud accounts in highly targeted campaigns.

WHY IT MATTERS

OAuth abuse allows attackers to bypass traditional phishing detection by exploiting legitimate authentication flows. This increases the risk of undetected account compromise for engineers and operators in sensitive sectors. The shift to OAuth-based attacks makes social engineering harder to spot without additional scrutiny.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Three Russian-linked groups are using OAuth phishing to target fewer than 100 individuals in aerospace, defense, and government sectors.

02

Attackers impersonate US State Department or diplomatic event invitations to trick victims into granting account access via OAuth verification codes.

03

Google tracks these groups separately due to differences in sophistication, infrastructure, and malware deployment tactics.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

Russian cyber-espionage groups have incorporated OAuth abuse into their phishing campaigns, marking a tactical shift from traditional credential harvesting. By leveraging legitimate authentication flows, attackers reduce the likelihood of detection by security tools that flag suspicious login pages. The method relies on victims unknowingly granting permissions via OAuth verification codes, which provide persistent access to email and cloud accounts without requiring passwords. This approach is particularly effective against targets in aerospace, defense, and government sectors, where multi-factor authentication is common but may not protect against OAuth token misuse.

The campaigns are highly targeted, with fewer than 100 individuals per operation and under 10 confirmed victims. This suggests the groups prioritize stealth and long-term access over broad-scale attacks. Google’s tracking of three distinct groups, UNC6293, UNC7005, and UNC5976, indicates a coordinated effort with varying levels of sophistication. UNC6293, linked to APT29 (Cozy Bear), has been active for nearly two years, while UNC7005 exhibits lower operational security and relies on malware deployment. The reuse of phishing templates, such as spoofed diplomatic event invitations, demonstrates a pattern of exploiting predictable human behavior in high-stakes environments.

For engineers and security teams, the shift to OAuth abuse complicates detection and response. Traditional phishing indicators, like fake login pages, are absent, and the attack surface expands to include any service supporting OAuth. The campaigns also highlight the risks of public Wi-Fi networks, where attackers have deployed captive portals to deliver malware. Mitigation requires user education on OAuth permissions, monitoring for unusual token grants, and enforcing strict conditional access policies. The ongoing nature of these campaigns suggests they will persist, with attackers likely refining their tactics to evade detection further.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
www.theregister.com - Articles Russian snoops add OAuth abuse to targeted phishing campaigns Open ↗