StratosAlly – Cybersecurity for digital safety

Russian Hackers Turn Legitimate Google and WhatsApp Features Into Phishing Weapons

Picture of StratosAlly

StratosAlly

Russian Hackers Turn Legitimate Google and WhatsApp Features Into Phishing Weapons

Cyberattacks don’t always arrive looking dangerous. Sometimes, they look like a normal Google login, a conference invitation, or a WhatsApp device-linking request.

Google’s Threat Intelligence Group (GTIG) is warning that three suspected Russian cyber-espionage groups, UNC6293, UNC7005, and UNC5976, are exploiting legitimate authentication features to quietly compromise accounts belonging to people in academia, aerospace, defense, government, diplomacy, and think tanks across Europe and the U.S.

The campaigns are highly selective. Google told The Register that each campaign involved fewer than 100 targets, with fewer than 10 victims in some cases. But the low volume is part of what makes them difficult to spot: these aren’t mass phishing emails. They are carefully tailored attacks designed to look believable.

One of the most concerning techniques involves OAuth, the authentication mechanism people use every day to sign into services with their Google account.

UNC5976, for example, created fake file-sharing websites and cloud infrastructure. A victim would see a familiar-looking page and click “Continue with Google.” The user is then taken to a legitimate Google authentication page, making the interaction appear trustworthy.

After authentication, however, the victim is redirected through attacker-controlled cloud infrastructure designed to capture the authentication token. That token can then be used to access the account without simply stealing a password. Google says UNC5976 created at least 12 domains and related infrastructure since March 2026, although those have since been disrupted.

UNC6293 has used a similar approach, impersonating U.S. State Department officials and sending highly targeted diplomatic-themed messages. In June, victims were asked to provide a verification code or full URL after completing a legitimate login — effectively handing attackers access to their accounts.

UNC7005 has taken the same “make it look legitimate” approach to WhatsApp.

Victims were directed to fake pages encouraging them to link their WhatsApp account to an attacker-controlled device to join a supposedly secure call, chat, or document exchange. Once linked, attackers could potentially access the account and, in some cases, trigger malicious JavaScript capable of recording audio and video during a call.

The group has also distributed infostealers disguised as a “Summit Companion App,” targeting researchers, diplomats, and academics working on Russia and former Soviet states.

Let’s refine your stalking skills; go through our Instagram and LinkedIn.

more Related articles