{
  "id": 2313880,
  "title": "Russian snoops add OAuth abuse to targeted phishing campaigns",
  "url": "https://urgent.news/2026/08/21/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T00:19:25.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/08/21/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns/5290706"
  },
  "original_language": "en",
  "account": "Google is monitoring three suspected Russian cyber-spy groups targeting individuals in academia, aerospace, defense, government agencies, and think tanks across Europe and the US. These UNC groups have been conducting highly targeted phishing campaigns since last year, with this activity continuing in the present month. Each campaign involved fewer than 100 targets and fewer than 10 victims, although the threat-intel team noted that if you work in government, NGOs, academia, or aerospace, you may be a target. The Russian cyber operatives have adapted their attacks by abusing legitimate authentication flows, making these social engineering tactics seem more legitimate and allowing them to compromise personal accounts across multiple platforms. One of the three groups, UNC6293, has been tracked by Google for nearly two years. This suspected APT29 (Cozy Bear) phishing squad impersonates US State Department employees to gain long-term access to victims' email correspondence. In June 2026, Google Threat Intelligence Group observed UNC6293 phishing for app passwords belonging to individuals critical of Russia. The group used the lure of impersonating State Department personnel and added OAuth phishing to their toolkit. Another group, UNC7005, is also tracked by Google with moderate confidence. This group primarily targets academia, diplomatic, and nonprofit personnel in Ukraine, Western Europe, and the US. They also abuse OAuth flows and employ device-code phishing for Microsoft and WhatsApp accounts. In May and June, UNC7005 conducted voice call, encrypted chat, and file download phishing lures, which download malware onto victims' devices. The third group, UNC5976, is another suspected Russian cyber-spy group.",
  "summary": "Don't click on that State Department meeting invite",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Russian snoops add OAuth abuse to targeted phishing campaigns",
        "url": "https://urgent.news/2026/08/21/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns-2318083",
        "published": "2026-08-21T00:19:25.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}