Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three suspected Russian espionage groups are exploiting legitimate Google OAuth and WhatsApp linking processes to hijack accounts of individuals in sensitive sectors.

Three distinct threat clusters, identified as UNC6293, UNC7005, and UNC5976, have been observed employing sophisticated tactics that leverage legitimate authentication flows to compromise accounts. These groups are suspected to be Russian state-sponsored espionage actors, and their targets include individuals working in academia, aerospace and defense, government sectors, and think tanks across Europe and the United States.
The primary technique involves the abuse of Google OAuth, a widely used authorization framework that allows users to grant third-party applications access to their data without sharing their credentials. By manipulating this process, the attackers can trick users into authorizing malicious applications, thereby gaining unauthorized access to their Google accounts. This method bypasses traditional security measures that focus on credential theft, as it relies on user consent, albeit coerced through social engineering.
Furthermore, the threat actors are reportedly exploiting the linking feature between Google accounts and WhatsApp. This integration allows users to manage their WhatsApp data and settings through their Google account. By gaining control of a user's Google account, the attackers can potentially gain access to linked WhatsApp data or use the compromised account to send malicious messages or impersonate the user.
The targeted sectors—academia, aerospace, defense, and government—suggest a focus on intelligence gathering and espionage. Compromising accounts within these fields could provide attackers with access to sensitive research, proprietary information, classified data, or strategic communications. The geographical focus on Europe and the U.S. aligns with typical geopolitical cyber espionage objectives.
While the specific details of the exploitation chain are still emerging, the reliance on legitimate authentication mechanisms highlights a growing trend in cyberattacks. Attackers are increasingly moving away from exploiting software vulnerabilities to focusing on exploiting human trust and the intricacies of complex authentication and authorization systems. This approach can be more effective and harder to detect.
Security researchers are urging organizations and individuals in the affected sectors to remain vigilant. This includes scrutinizing any requests for account authorization, especially those involving Google OAuth or linked services. Implementing multi-factor authentication (MFA) on all accounts, particularly Google accounts, is a critical defense layer. Additionally, users should regularly review connected applications and revoke access for any suspicious or unnecessary services.
The involvement of multiple distinct clusters (UNC6293, UNC7005, and UNC5976) suggests a coordinated or at least a shared operational methodology among suspected Russian intelligence-linked groups. This coordinated effort, even if not directly managed, indicates a sustained interest in these targets and methods.
This campaign underscores the evolving threat landscape where attackers are adept at weaponizing legitimate services. The abuse of OAuth and account linking features presents a significant challenge for defenders, as it blurs the lines between legitimate access and malicious activity, making detection and prevention more complex.
Google's Threat Intelligence Group has identified two additional suspected Russian espionage groups, UNC7005 and UNC5976, which are also employing phishing and OAuth abuse tactics. UNC7005, in particular, has been observed using captive portals and device-code phishing, with some operations appearing to be AI-assisted, and targets individuals in academia, diplomatic, and nonprofit sectors across Europe and the US.
This new reporting provides further detail on the tactics employed by the Russian-linked threat groups UNC6293, UNC7005, and UNC5976, highlighting their use of social engineering with lures such as conference invitations and diplomatic themes to trick victims into approving seemingly legitimate authentication requests. The article also elaborates on the specific mechanisms of abuse, including the misuse of OAuth flows and WhatsApp device linking to capture access tokens and gain linked sessions, and notes the distribution of malware like VIDAR and ATOMIC against Windows and macOS users respectively.