# Russian Espionage Groups Exploit OAuth and WhatsApp for Account Hijacking

*Published August 24, 2026*
*Source: [https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html)*

## Executive Summary

Three Russian cyber espionage clusters have been identified exploiting OAuth and WhatsApp processes to hijack accounts in academia, aerospace and defense, and government sectors across Europe and the U.S. These attacks highlight the sophisticated tactics used by state-sponsored actors to compromise sensitive information.

## Article

Researchers from Google's Threat Intelligence Group have identified three distinct Russian cyber espionage clusters exploiting legitimate authentication processes to target individuals in academia, aerospace and defense, government sectors, and think tanks across Europe and the U.S. These groups, identified as UNC6293, UNC7005, and UNC5976, employ advanced phishing tactics to compromise accounts. UNC6293, associated with the notorious hacking group Ice Relic, employs phishing campaigns that impersonate State Department officials to trick fewer than five users at a time into divulging app passwords. This group has been active since June 2025 and continues to use OAuth phishing to gain unauthorized access to accounts. UNC5976, on the other hand, has been using OAuth phishing techniques since at least March 2026. The group creates fake file-sharing domains and cloud projects to lure victims into providing authentication tokens, which are then exploited. Despite Google's disruption of their infrastructure, UNC5976 has adapted by shifting to other providers. Their operations have heavily targeted military and aerospace sectors in Ukraine and Armenia. Lastly, UNC7005, also known as Storm-2945, primarily targets academia, diplomatic, and nonprofit personnel. They have engaged in phishing operations using WhatsApp and OAuth to compromise accounts. Their recent campaigns include spoofing Finnish defense organizations and targeting users related to NATO. This group has also incorporated commodity malware to exfiltrate data from compromised systems. These sophisticated attacks underscore the persistent threat posed by state-sponsored espionage actors and highlight the need for robust security measures to protect sensitive information.
