Russia-Linked Cyber Espionage Clusters Use OAuth Phishing to Target U.S. and European Organizations
Brief
Google Threat Intelligence Group (GTIG) has detailed several Russia-linked cyber espionage clusters targeting people in academia, think tanks, and other organizations in the United States and Europe.
The activity involves OAuth phishing, device-code phishing, spoofed websites, and infrastructure designed to imitate trusted organizations and cloud services.
The tracked clusters UNC6293, UNC7005, and UNC5976 show different levels of operational maturity. However, their campaigns rely on a common goal: convincing targets to grant attackers access to email, cloud accounts, or messaging platforms.
UNC6293 used the domains foreignrelations[. ]us and dosportal[. ]app in OAuth phishing campaigns . The first domain was registered and became active on November 21, 2025, after years without DNS activity.
