Start with Identity
← Blog
News

Three Russian clusters move from password phishing to OAuth token theft

Google Threat Intelligence Group tracked UNC6293, UNC7005, and UNC5976 abusing device-code flow, verification-code relay, and fake Continue with Google pages to take authenticated sessions rather than passwords.

By SWI Community TeamAug 21, 2026Updated Aug 29, 2026

Google Threat Intelligence Group reported on August 21, 2026 that three suspected Russian clusters have added OAuth abuse to their targeted phishing. UNC6293, linked to the SVR and overlapping with APT29, asks targets to share verification codes after a legitimate login. UNC7005 runs device-code phishing against Microsoft and WhatsApp accounts from attacker-controlled sites. UNC5976 serves fake file-sharing pages with a "Continue with Google" button that routes through the real Google login and captures the resulting tokens through Google Cloud project URLs. Targets are academia, aerospace, defense, government, think tanks, and Russia-focused researchers across Europe and the US, fewer than 100 per campaign and under 10 confirmed victims.

Why it matters

Espionage crews adopt a technique when it beats the defences their targets actually deploy. All three of these paths end with the attacker holding a legitimate token rather than a password, which means a password reset does nothing and the sign-in looks normal in the log because it was normal. Device-code flow is the recurring offender: it was designed for input-constrained devices like TVs and consoles, and it deliberately decouples the device requesting access from the device approving it, which is exactly the property a phisher wants. If your tenant has no smart TVs in it, disable device-code flow by policy. Otherwise scope it, alert on device-code grants from unexpected clients, and read our token theft entry for the containment steps.

Source: The Register

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.