Russian Clusters Target Individuals via Authentication Abuse
Score: 8/10

Russian Clusters Target Individuals via Authentication Abuse

Suspected Russian clusters UNC6293, UNC7005, and UNC5976 are abusing legitimate authentication flows like OAuth and app passwords to target individuals in government, defense, and academia.

Executive Summary

Google Threat Intelligence Group is tracking three distinct Russian-nexus clusters—UNC6293, UNC7005, and UNC5976—abusing legitimate authentication workflows to compromise targets in academia, aerospace, defense, and government sectors across Europe and the US. These actors, particularly UNC7005 (linked to ICE RELIC/APT29), employ sophisticated social engineering to trick victims into creating app passwords or authorizing malicious OAuth tokens.

The technical focus has shifted toward evading standard security controls by leveraging legitimate infrastructure and 'Malware-as-a-Service' (MaaS) such as VIDAR and ATOMIC. Notably, UNC7005 was identified in a campaign redirecting users from hospitality captive portals (hotels/conferences) to malicious infrastructure, highlighting a persistent interest in targeting travelers and diplomatic personnel. The use of LLM-generated malware and residential proxies further complicates attribution and detection efforts.

Key Details

Threat Name

UNC7005 Russian Cyber Espionage Cluster

Affects

—

Adversary

UNC6293 Other Adversaries and Aliases: UNC7005; UNC5976; Midnight Blizzard

Malware/Tools

VIDAR, ATOMIC, ENGINELIGHT, CHERRYPIE, HEADRUSH

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure10
Technical Depth8

Sources