Threat Intelligence

Suspected Russian Hackers Exploit Google and WhatsApp Login Features to Hijack Accounts

The Hacker News · 21 Aug 2026
Key Takeaway Train staff to scrutinise any unexpected login or device-linking requests—even from trusted platforms like Google or WhatsApp—before approving them.

Cybersecurity researchers have uncovered three distinct threat clusters, tracked as UNC6293, UNC7005, and UNC5976, believed to be linked to Russian state-sponsored espionage activity. Rather than relying on traditional malware, these groups are abusing legitimate authentication processes—specifically Google's OAuth login system and WhatsApp's device-linking feature—to gain unauthorised access to victims' accounts.

The campaigns have primarily targeted individuals working in academia, aerospace and defence, government agencies, and think tanks across Europe, as well as similar sectors in the United States. By exploiting trusted sign-in mechanisms rather than exploiting software vulnerabilities, attackers can trick victims into unknowingly granting account access, making these attacks harder to detect through conventional security tools.

This approach reflects a broader trend among sophisticated threat actors: using persistent, adaptive social engineering combined with abuse of legitimate platform features rather than relying solely on malicious code. While the primary targets have been high-profile institutions, the underlying techniques—phishing links disguised as login requests or device-linking prompts—could just as easily be adapted against smaller organisations that use the same widely deployed platforms.

phishing account hijacking OAuth security state-sponsored hackers WhatsApp security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.