Cybersecurity Research

Russian State-Linked Hackers Exploit Login Systems to Target High-Profile Individuals

Key Takeaway Be cautious of any unsolicited instructions asking you to create or change 'app passwords' or approve unfamiliar app permissions, even if they appear to come from a trusted organisation.

Google Threat Intelligence Group (GTIG) has identified three distinct suspected Russian cyber espionage clusters that are exploiting legitimate login and authentication systems to compromise accounts belonging to individuals of interest to Russia. Targets include people working in academia, aerospace and defence, government bodies and think tanks across Europe and the United States. Rather than relying purely on traditional phishing links, these groups are abusing trusted authentication flows like app passwords and OAuth, techniques that can look legitimate to the victim and are harder to spot than typical scam emails.

One group, tracked as UNC6293 and assessed with moderate confidence to be linked to the well-known Russian espionage actor formerly called APT29, has impersonated the US State Department in past campaigns. Victims were sent a PDF with instructions and screenshots convincing them to set up a specific 'app password', a special access code meant for less secure apps, which the attackers then used to bypass two-factor authentication and log into the victim's account directly. Two further clusters, UNC7005 and UNC5976, use similar social engineering tactics involving phishing, OAuth abuse and malware, with UNC7005 linked to prior reports of malicious redirects through hotel and hospitality Wi-Fi login portals.

GTIG notes that because these attacks abuse real authentication processes, they can be difficult for even security-conscious users to recognise as malicious, which is why raising awareness of these tactics is an important defence in itself.

Russia phishing account takeover OAuth abuse espionage

Summarised by CISO AI from Google Threat Intelligence. We link back to every original so you can read it yourself.