VYPR
researchPublished Aug 20, 2026· Updated Aug 27, 2026· 6 sources

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three suspected Russian espionage groups are exploiting legitimate Google OAuth and WhatsApp linking processes to hijack accounts of individuals in sensitive sectors.

Three distinct threat clusters, identified as UNC6293, UNC7005, and UNC5976, have been observed employing sophisticated tactics that leverage legitimate authentication flows to compromise accounts. These groups are suspected to be Russian state-sponsored espionage actors, and their targets include individuals working in academia, aerospace and defense, government sectors, and think tanks across Europe and the United States.

The primary technique involves the abuse of Google OAuth, a widely used authorization framework that allows users to grant third-party applications access to their data without sharing their credentials. By manipulating this process, the attackers can trick users into authorizing malicious applications, thereby gaining unauthorized access to their Google accounts. This method bypasses traditional security measures that focus on credential theft, as it relies on user consent, albeit coerced through social engineering.

Furthermore, the threat actors are reportedly exploiting the linking feature between Google accounts and WhatsApp. This integration allows users to manage their WhatsApp data and settings through their Google account. By gaining control of a user's Google account, the attackers can potentially gain access to linked WhatsApp data or use the compromised account to send malicious messages or impersonate the user.

The targeted sectors—academia, aerospace, defense, and government—suggest a focus on intelligence gathering and espionage. Compromising accounts within these fields could provide attackers with access to sensitive research, proprietary information, classified data, or strategic communications. The geographical focus on Europe and the U.S. aligns with typical geopolitical cyber espionage objectives.

While the specific details of the exploitation chain are still emerging, the reliance on legitimate authentication mechanisms highlights a growing trend in cyberattacks. Attackers are increasingly moving away from exploiting software vulnerabilities to focusing on exploiting human trust and the intricacies of complex authentication and authorization systems. This approach can be more effective and harder to detect.

Security researchers are urging organizations and individuals in the affected sectors to remain vigilant. This includes scrutinizing any requests for account authorization, especially those involving Google OAuth or linked services. Implementing multi-factor authentication (MFA) on all accounts, particularly Google accounts, is a critical defense layer. Additionally, users should regularly review connected applications and revoke access for any suspicious or unnecessary services.

The involvement of multiple distinct clusters (UNC6293, UNC7005, and UNC5976) suggests a coordinated or at least a shared operational methodology among suspected Russian intelligence-linked groups. This coordinated effort, even if not directly managed, indicates a sustained interest in these targets and methods.

This campaign underscores the evolving threat landscape where attackers are adept at weaponizing legitimate services. The abuse of OAuth and account linking features presents a significant challenge for defenders, as it blurs the lines between legitimate access and malicious activity, making detection and prevention more complex.

Google's Threat Intelligence Group has identified two additional suspected Russian espionage groups, UNC7005 and UNC5976, which are also employing phishing and OAuth abuse tactics. UNC7005, in particular, has been observed using captive portals and device-code phishing, with some operations appearing to be AI-assisted, and targets individuals in academia, diplomatic, and nonprofit sectors across Europe and the US.

This new reporting provides further detail on the tactics employed by the Russian-linked threat groups UNC6293, UNC7005, and UNC5976, highlighting their use of social engineering with lures such as conference invitations and diplomatic themes to trick victims into approving seemingly legitimate authentication requests. The article also elaborates on the specific mechanisms of abuse, including the misuse of OAuth flows and WhatsApp device linking to capture access tokens and gain linked sessions, and notes the distribution of malware like VIDAR and ATOMIC against Windows and macOS users respectively.

This latest report from Google Threat Intelligence details three distinct Russian-linked threat clusters, UNC6293, UNC7005, and UNC5976, actively exploiting legitimate OAuth flows from Google and Microsoft. While the existing report broadly covers this tactic, this new article provides specific details on the operational methodologies, infrastructure, and varying sophistication levels of these groups, including UNC7005's use of malware and UNC5976's focus on military targets. It also highlights the exploitation of personal accounts, which creates a visibility gap for organizations.

This latest reporting expands on previous findings by detailing specific infrastructure and tactics used by the Russian-linked threat actors. Validin's analysis highlights the use of convincing Google Drive lookalike domains and diplomatic-themed lures, including references to the Council on Foreign Relations and the Washington Ballet, to trick victims into authorizing malicious applications via OAuth. The campaigns also employed proxy-based phishing techniques, potentially using Evilginx configurations, to intercept sign-in sessions for Microsoft and WhatsApp accounts.

This new reporting indicates a strategic shift by Russian nation-state actors, moving beyond exploiting Google OAuth and WhatsApp linking mechanisms to directly target EU officials through messaging apps like Signal and WhatsApp. The focus has broadened from account hijacking to a more direct phishing approach, prompting EU governments to re-evaluate their communication security protocols.

Synthesized by Vypr AI