← Back to feed
PhishingEmerging1 sourceAug 20, 2026 · 14:00via Mandiant / Google TI

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Brief

Written by: Gabby Roncone, Wesley Shields

Overview

Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States.

Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an additional two distinct suspected Russian clusters, UNC7005 and UNC5976, which conduct phishing, abuse OAuth flows, and/or deploy malware to victims. UNC7005 in particular is tied to the hospitality captive portal redirects reported on by Reliaquest and Microsoft .

Read more on Mandiant / Google TI