
Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features across WhatsApp, Google, and Microsoft to compromise academics, diplomats, defense personnel, researchers, and government-linked individuals.
One cluster, tracked as UNC7005, has gone so far as to trick victims into linking WhatsApp accounts to attacker-controlled devices and recording their audio and video through fake calls.
Google tracks the activity as UNC6293, UNC7005, and UNC5976, assessing with high confidence that all three have a Russian nexus. UNC6293 and UNC7005 are further assessed with moderate confidence as initial-access clusters associated with ICE RELIC, Google's name for the threat actor also known as APT29.
Google’s researchers said the campaigns are particularly difficult to spot because they frequently abuse genuine authentication mechanisms rather than relying on conventional fake login pages.
UNC7005, also tracked as STORM-2945, began targeting academics, diplomats, nonprofits, and researchers in Ukraine, Western Europe, and the United States in early 2026. During May and June, the group created phishing pages impersonating WhatsApp and invited targets to join supposedly secure calls, chats, or document-sharing sessions.

Victims were first asked for their phone number. The attackers then initiated a legitimate WhatsApp device-linking request and displayed its genuine QR code or linking code on the phishing page. Anyone following the instructions effectively authorized an attacker-controlled device to access their WhatsApp account.

After linking succeeded, UNC7005 presented additional traps. Selecting a supposed voice call caused JavaScript to request camera and microphone access, record the victim during a fake ringing sequence, and upload the resulting WebM recording to an attacker-controlled command-and-control endpoint. Other options directed victims to a fake encrypted-chat login or offered a file download whose payload GTIG could not determine.

UNC7005 has used several other infection methods. Microsoft device-code phishing pages impersonated diplomatic events such as GLOBSEC and fingerprinted visitors to detect automated analysis. The group also deployed VIDAR on Windows and AtomicStealer on macOS through a fake “Summit Companion App,” targeting browser credentials, cookies, payment details, and other stored information.
Google additionally linked UNC7005 infrastructure to compromised hotel and conference-center captive portals reported by ReliaQuest and Microsoft. Those redirects led users to Microsoft-themed phishing infrastructure capable of device-code theft or malware delivery. GTIG also identified ENGINELIGHT malware and overlaps with the CHERRYPIE/ChocoShell PowerShell infostealer, whose code contained artifacts suggesting LLM-assisted generation.
The other clusters use related authentication attacks. UNC6293 has impersonated the US State Department to convince targets to create app passwords or surrender OAuth verification codes, while UNC5976 has built fake file-sharing sites that redirect victims through legitimate Google OAuth pages before stealing authentication tokens. UNC5976 also deployed a malicious Excel plugin dubbed HEADRUSH, which led to an HTA downloader.
Users should treat unexpected requests to link messaging devices, enter device codes, create app passwords, or approve OAuth access as suspicious. WhatsApp users should regularly review linked devices, enable two-step verification and registration protections, and verify sensitive invitations through a separate trusted channel.







Leave a Reply