GTIG Tracks Three Russian Clusters Abusing Login Flows

Google Threat Intelligence Group says it is now tracking three suspected Russian espionage clusters that abuse legitimate sign-in flows, including UNC6293 and two newly identified groups, UNC7005 and UNC5976. The activity targets academia, aerospace and defense, governments, and think tanks across Europe and the United States. Instead of stealing a password and stopping there, the campaigns push victims through real-looking account steps: application-specific passwords, OAuth consent screens, captive-portal redirects, and malware delivery. That can give attackers a standing way back into the account, so a password reset alone may not clear the compromise if the granted access remains in place. The shift matters anywhere SaaS accounts carry trust. If an organization relies on app passwords or consented OAuth access, the exposure can sit in the authorization layer rather than in the password itself, and that makes normal phishing defenses easier to miss.

Part of the PlainSec briefing for 2026-08-20

Editions

Sources