Cyber Insights: Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

2nd September 2026

2nd September 2026

Google security researchers have uncovered a series of highly targeted cyber-espionage campaigns in which suspected Russian threat actors are abusing legitimate authentication features across Google, Microsoft and WhatsApp to gain access to sensitive accounts.
Google Threat Intelligence Group (GTIG) identified three clusters — UNC6293, UNC7005 (Storm-2945) and UNC5976 — using Google OAuth phishing, Microsoft device-code authentication and WhatsApp device linking to obtain legitimate sessions and authentication tokens rather than simply stealing passwords.
Targets include individuals working across government, diplomacy, academia, aerospace, defence, NGOs and think tanks in Europe, Ukraine and the United States. Google assesses UNC6293 and UNC7005 as associated with a subgroup of Ice Relic, formerly APT29 and also known as Cozy Bear or Midnight Blizzard. The campaigns highlight an increasingly important challenge for defenders: a successful authentication does not necessarily mean the legitimate user is in control of the session.
A defining feature of these campaigns is that victims may actually be presented with genuine Google or Microsoft authentication services.
UNC5976, for example, created fake file-sharing websites offering users a familiar “Continue with Google” option. Selecting it redirects the victim to Google’s legitimate OAuth authentication page.
Once authentication is completed, however, the victim is redirected to an attacker-controlled cloud project where authentication information can be extracted and used to hijack the account.
UNC7005 has applied a similar principle to Microsoft device-code authentication. Victims are persuaded to complete a legitimate authentication request that ultimately authorises an attacker-controlled session. MFA may therefore be successfully completed even though access is being granted to the wrong party.
For defenders, this means the context surrounding authentication is becoming just as important as whether authentication itself was successful.
The attackers have developed another variation of the technique to compromise WhatsApp accounts.
A phishing site first requests the victim’s phone number, which is then used to initiate a genuine WhatsApp device-linking request from an attacker-controlled device. The victim is shown the legitimate QR code or linking code and encouraged to complete the process.
If successful, the attacker’s device becomes linked to the WhatsApp account, potentially providing access to the victim’s communications.
Researchers also found that subsequent phishing pages could attempt further exploitation, including credential theft and even the capture of audio and video. For executives, diplomats, researchers and other high-value personnel, unexpected WhatsApp device-linking requests should therefore be treated as a potential account-compromise indicator.
The common thread across these campaigns is the abuse of trusted services and authentication processes.
Instead of attempting to defeat MFA or break into an account directly, attackers are manipulating victims into completing legitimate authentication on their behalf. The resulting OAuth tokens, authenticated sessions or linked devices can then provide access without generating the obvious warning signs associated with a stolen password.
Once inside a legitimate cloud account, attackers may gain access to emails, documents, conversations and organisational contacts. Compromised accounts can also be used to target colleagues or external contacts, exploiting the trust already associated with the victim’s identity. The targeting profile makes the campaign particularly relevant to UK government, defence and aerospace organisations, with the groups demonstrating sustained interest in diplomats, defence-sector personnel, academics and researchers.
Some of the activity overlaps with the CaptiveCrunch campaign, which targets Wi-Fi infrastructure at hotels, conference centres and airports.
By compromising Wi-Fi gateways and manipulating DNS responses, attackers can redirect selected users towards malicious authentication infrastructure without first compromising their devices.
Researchers have also identified a possible MSP supply-chain element, where compromised service providers may have enabled access to Wi-Fi infrastructure managed on behalf of multiple customers. This further demonstrates how identity attacks can begin outside an organisation’s traditional security perimeter.
Security teams should avoid treating successful authentication as proof that an account is secure. Instead, identity events should be correlated with browser, endpoint, network and DNS activity to understand what happened before and after authentication.
Particular attention should be given to:
Conventional phishing controls may not identify these campaigns because genuine Google and Microsoft authentication pages can form part of the attack chain.
Organisations should restrict unnecessary third-party OAuth consent and monitor new applications requesting access to corporate accounts.
Microsoft Entra ID Conditional Access policies should be reviewed to control device-code authentication where possible, while phishing-resistant MFA should be prioritised for high-value users.
Where compromise is suspected, simply resetting the password may not be sufficient. Security teams should revoke active sessions and tokens, remove unauthorised linked devices and review recently added authentication methods. High-risk personnel should also be reminded never to provide authentication codes to another person or scan WhatsApp linking codes at the direction of an unfamiliar website — even when the subsequent Google, Microsoft or WhatsApp interface appears genuine.
The GTIG research demonstrates a mature cyber-espionage strategy built around manipulating legitimate authentication rather than simply defeating it.
This is particularly significant because a valid Google login, successful Microsoft MFA challenge or legitimate WhatsApp device link can all occur during an attacker-controlled compromise.
For organisations handling sensitive government, defence, aerospace or research information, the priority should be improving visibility around authentication context, OAuth activity and session creation. Rapid token revocation and the ability to correlate identity events with endpoint and network telemetry will become increasingly important as these techniques evolve.
As attackers increasingly target authentication tokens and trusted sessions, organisations need visibility beyond passwords and malware alerts. NormCyber’s Managed Detection and Response (MDR) service continuously monitors identity, endpoint and network telemetry to identify suspicious activity that may otherwise appear legitimate.
Our SOC analysts investigate anomalous sign-ins, unusual OAuth activity, suspicious session behaviour and unexpected authentication events, correlating these signals with activity across the wider environment. This helps identify when a seemingly legitimate account is actually being controlled or exploited by a threat actor.
With 24/7 expert monitoring and response, NormCyber MDR helps organisations identify compromised identities earlier, contain suspicious sessions and prevent trusted accounts from becoming the starting point for a wider attack.
Primary: Google Threat Intelligence Group – Distinct Clusters Target Individuals of Interest to Russia