Executive Summary
Google Threat Intelligence Group is tracking three distinct Russian-nexus clusters—UNC6293, UNC7005, and UNC5976—abusing legitimate authentication workflows to compromise targets in academia, aerospace, defense, and government sectors across Europe and the US. These actors, particularly UNC7005 (linked to ICE RELIC/APT29), employ sophisticated social engineering to trick victims into creating app passwords or authorizing malicious OAuth tokens.
The technical focus has shifted toward evading standard security controls by leveraging legitimate infrastructure and 'Malware-as-a-Service' (MaaS) such as VIDAR and ATOMIC. Notably, UNC7005 was identified in a campaign redirecting users from hospitality captive portals (hotels/conferences) to malicious infrastructure, highlighting a persistent interest in targeting travelers and diplomatic personnel. The use of LLM-generated malware and residential proxies further complicates attribution and detection efforts.
