Urgent.News

What's breaking now, across thousands of outlets.

Editions

Tech

Russian snoops add OAuth abuse to targeted phishing campaigns

Don't click on that State Department meeting invite

Russian snoops add OAuth abuse to targeted phishing campaigns

Google is monitoring three suspected Russian cyber-spy groups targeting academics, aerospace professionals, defense personnel, government agencies, and think tanks in Europe and the US. These groups, known as UNC, have been conducting targeted campaigns since last year and continue to do so. Each campaign has fewer than 100 targets and under 10 victims.

Despite the small numbers, the Russian cyber-spy groups have adapted their tactics by abusing OAuth authentication flows, making the social engineering attempts appear more legitimate and allowing them to compromise personal accounts across multiple platforms. Two of the groups, UNC6293 and UNC7005, have been specifically identified as posing as US State Department employees and targeting academia, aerospace, defense, government agencies, and think tanks.

UNC6293 has been linked to the 2020 SolarWinds hack and is believed to be connected to Russia's Foreign Intelligence Service (SVR). UNC7005, on the other hand, is less sophisticated but shares similarities with UNC6293. Google urges targets to be cautious of phishing attempts, especially those that appear to come from government entities, and advises not to trust any unsolicited communications blindly.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

The Principle of Least Privilege: Why File Permissions Like 600/644/755 Exist

Anyone who has worked with SSH private keys has run into an instruction to "set it to 600." Config files, by contrast, often get 644, and executable scripts get 755.

  • File permissions 600/644/755 represent Unix-style access rights.
  • Each number breaks down into owner, group, others, and read/write/execute.
  • Principle of least privilege guides granting minimal required access.

More from Friday 21 August →