Google links three Russian threat clusters to OAuth phishing of high-value targets
This digest was compiled by AI from multiple sources — links to the originals are below.

Google Threat Intelligence identified three Russia-linked threat clusters abusing legitimate OAuth authentication to steal data from targeted individuals in Europe and the United States. The groups impersonate legitimate organizations and redirect victims through real Google and Microsoft login flows to capture authentication data. Two clusters are likely sub-units of the Russian Foreign Intelligence Service actor known as Cozy Bear, while the third remains separate.
Key Facts
- Google Threat Intelligence identified three Russia-linked threat clusters abusing legitimate OAuth authentication to steal information from targeted individuals as recent as August 2026.
- Two clusters, UNC6293 and UNC7005, are likely sub-units of the Russian Foreign Intelligence Service actor known as Cozy Bear, Midnight Blizzard, or APT29.
- Targets include individuals from academia, aerospace and defense, governments, and think tanks across Europe and the United States.
- UNC6293 has conducted OAuth phishing since at least June 2025, initially impersonating the U.S. Department of State to lure targets into generating app-specific passwords for Gmail.
- UNC7005, also tracked as Storm-2945, was identified in February 2026 and began phishing campaigns abusing Google account OAuth earlier in August 2026.
Threat Clusters and Attribution
Google Threat Intelligence is tracking three Russia-linked threat clusters that abuse legitimate authentication mechanisms to steal information from small groups of targeted individuals. Two of the separately tracked actors, UNC6293 and UNC7005, are likely sub-units of the Russian Foreign Intelligence Service threat actor Google calls Ice Relic, also known as Cozy Bear, Midnight Blizzard, and APT29. The third cluster, UNC5976, remains separate from the other two. The groups impersonate legitimate organizations and lead victims through real Google and Microsoft OAuth flows, then steal authentication data through attacker-controlled redirects, malicious cloud projects, or prompts asking victims to submit it directly.
Targeting and Operational Tactics
The small number of high-value targets include individuals from academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the United States. The accounts these groups target are often personal, rather than corporate domain-joined accounts, creating a visibility gap for monitoring compromise from an organizational perspective. UNC6293's operations were initially reported in June 2025 as a password phishing campaign in Russia's interest that impersonated the U.S. Department of State and attempted to lure targets into generating personal app-specific passwords for Google Gmail. In June 2026, Google observed OAuth phishing where UNC6293 requested targets share either the full URL or verification code after performing a legitimate login to an external provider, granting the group access to the account. UNC7005, also tracked as Storm-2945, was identified in February 2026 and targeted similar organizations and regions as UNC6293, but is tracked separately due to its lower sophistication and poor operational security.
1 source
Google links three Russian threat clusters to OAuth phishing of high-value targets






