TL;DR
what: Google Threat Intelligence Group detailed three suspected Russian espionage clusters, UNC6293, UNC7005, and UNC5976, that phish authentication flows rather than passwords, using OAuth consent, application specific passwords, device code grants, and WhatsApp device linking.
Google Threat Intelligence Group published research on August 20, 2026 linking three suspected Russian espionage clusters to phishing campaigns that never ask for a password. UNC6293, UNC7005, and UNC5976 target academia, aerospace and defense, government, and think tank personnel across Europe, Ukraine, and the United States. All three attack the authentication flow itself: OAuth consent, application specific passwords, device code grants, and WhatsApp device linking. A completed MFA rollout stops none of it.
Three clusters, one operating model
GTIG researchers Gabby Roncone and Wesley Shields describe the activity as persistent and adaptive, focused on personal accounts across
Discussion
Start the conversation
Your voice can be the first to spark an engaging conversation.