Full Report
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive
Analysis Summary
# Threat Actor: UNC6293, UNC7005, and UNC5976 (Ice Relic/APT29 sub-clusters)
## Attribution & Identity
- **Primary Attribution:** Suspected Russian cyber espionage clusters.
- **UNC6293:** Assessed as a sub-cluster of **Ice Relic** (formerly **APT29**), also known as **Cozy Bear** and **Midnight Blizzard**.
- **UNC7005:** Also known as **Storm-2945**. Associated with Ice Relic's initial access operations.
- **UNC5976:** A distinct Russian-linked authentication-focused cluster.
## Activity Summary
These clusters have been active through 2025 and mid-2026, conducting persistent, small-scope phishing campaigns. They leverage legitimate authentication flows (OAuth) and social engineering to hijack personal and professional accounts. Notable activities include impersonating State Department officials and spoofing European security events.
## Tactics, Techniques & Procedures
- **OAuth Phishing:** Leveraging "Continue with Google" flows to trick users into granting access to malicious cloud projects.
- **App-Specific Password Abuse:** Seizing control of accounts by abusing Google’s application-specific password features.
- **Social Engineering:** Impersonating government/diplomatic officials and using lures related to upcoming conferences and meetings.
- **Token Theft:** Automating the collection of authentication tokens via malicious scripts hosted on Google Cloud Project URLs.
- **Account Linking Abuse:** Leveraging legitimate linking flows, including WhatsApp linking, to compromise accounts.
- **Residential Proxies:** Use of commercial residential proxies for post-compromise activity to mask origin.
- **Malware Delivery:** Use of rogue plugins to deliver HTA downloaders.
## Targeting
- **Sectors:** Academia, Aerospace and Defense, Government/Diplomatic, Think Tanks, NGOs, and the Defense Industrial Base.
- **Geography:** Europe (specifically Ukraine and Armenia), Western Europe, and the United States.
- **Victims:** Personnel at diplomatic organizations, Ukrainian research institutes, and a Ukrainian aerospace and imaging company.
## Tools & Infrastructure
- **HEADRUSH:** A rogue Excel plugin used to deliver an HTML Application (HTA) downloader.
- **Infrastructure:**
- Malicious Google Cloud Projects used for token staging.
- File-sharing-themed domains (e.g., used by UNC5976).
- Fake login dialogs and phishing pages impersonating Ukrainian research institutes.
- *Note: Specific IPs and URLs were not provided in the text, but the actor uses "file-sharing-related domain names."*
## Implications
These clusters demonstrate a strategic shift toward abusing legitimate authentication mechanisms (OAuth) rather than traditional credential harvesting. By targeting personal accounts of individuals in sensitive sectors, Russia-linked actors bypass corporate perimeter defenses to gain access to sensitive diplomatic and military communications. The use of small-scale, highly targeted campaigns (fewer than five users at a time) makes detection by broad security filters significantly more difficult.
## Mitigations
- **OAuth Governance:** Audit and restrict third-party application permissions within corporate environments.
- **MFA Hardening:** Transition from SMS/App-based MFA to FIDO2-compliant security keys to prevent session hijacking and OAuth abuse.
- **User Training:** Educate high-value targets on the risks of "Continue with [Provider]" prompts and the danger of sharing verification codes or full authentication URLs.
- **Token Monitoring:** Implement monitoring for unusual token generation or access from residential proxy networks.
- **Application Controls:** Disable or strictly monitor the use of "application-specific passwords" in cloud environments.