Russian Hackers Exploit Google OAuth and WhatsApp to Hijack High-Value Accounts

Hacker Russi Abusano di Google OAuth e WhatsApp per Rubare Account

Three Russia-linked cyber espionage clusters are actively abusing Google OAuth to compromise high-value accounts. Tracked as UNC6293, UNC7005, and UNC5976, these threat actors are targeting academics, aerospace companies, government bodies, and think tanks across Europe and the United States. The campaigns have been documented by the Google Threat Intelligence Group and corroborated by independent sources.


Attack Techniques: OAuth Abuse and WhatsApp in the Crosshairs

How Google OAuth Is Being Weaponized

The attack mechanism is sophisticated yet difficult to detect. Victims are redirected to fully legitimate Google login pages — the catch lies in the destination project: a Google Cloud Project secretly controlled by the attackers.

UNC5976, in particular, creates fake file-sharing pages featuring a “Continue with Google” button. When the victim clicks it, a genuine OAuth flow is triggered. After authentication, malicious scripts silently extract the OAuth token from the URL. That token grants the attackers full account access — no password required.

What makes this especially dangerous is that the victim sees nothing unusual. The login occurs on real Google infrastructure, with no visual warning signs whatsoever.

The WhatsApp Vector: Account Linking Turned Into a Weapon

Running in parallel, the UNC7005 cluster conducted social engineering campaigns between May and June 2026. Attackers impersonate trusted contacts and invite victims to join a secure call, a private chat, or to share a document.

Step-by-step instructions then guide the victim into linking their WhatsApp account to a new device. If the victim complies, the attacker’s device gains full access to the account — enabling real-time reading of messages, contacts, and shared files.


Targets and Threat Actors Involved

Who Russian Hackers Are Going After

These campaigns are anything but indiscriminate. The threat actors carefully select high-value strategic targets. Affected sectors include:

  • Academia and research
  • Aerospace and defense
  • Government agencies
  • Think tanks and policymakers

The geographic focus is equally deliberate, with operations concentrated on targets in Europe and the United States — a pattern consistent with Russia’s documented geopolitical interests in recent years.

The Three Clusters: UNC6293, UNC7005, UNC5976

Google Threat Intelligence has attributed the activity to three distinct clusters, each with its own operational characteristics, yet sharing a common objective: stealing credentials and authentication tokens without raising suspicion.

UNC5976 specializes in Google OAuth abuse through elaborate phishing pages. UNC7005 focuses on WhatsApp-based social engineering. UNC6293 is involved in the same campaign wave, though its specific operational details are still being analyzed.


Why These Attacks Are So Dangerous

Legitimacy as the Primary Weapon

The core strength of these campaigns is the exploitation of legitimate infrastructure. Rather than building clumsy fake websites, the attackers leverage Google and WhatsApp’s own authentication mechanisms — rendering many traditional security controls ineffective.

Furthermore, stolen OAuth tokens can remain valid for extended periods. A compromised token enables persistent access without the need for additional credentials, making password-only defenses wholly inadequate.

What Organizations and CISOs Should Do Now

In light of these threats, organizations must urgently revisit their authentication policies. Key immediate measures include:

  • Auditing OAuth permissions granted to third-party apps within Google accounts.
  • Regularly reviewing linked devices on WhatsApp and other messaging platforms.
  • Training staff to recognize unsolicited account-linking requests.
  • Deploying anomaly detection solutions for authentication tokens.
  • Adopting hardware security keys (FIDO2/WebAuthn) for the most sensitive accounts.

That said, technology alone is not enough. The human factor remains the primary entry point, and user awareness is an irreplaceable line of defense.


Conclusion

The exploitation of Google OAuth and WhatsApp by Russia-linked hackers represents a concrete and evolving threat. These actors demonstrate advanced operational capabilities, weaponizing users’ trust in the everyday platforms they rely on. For organizations operating in sensitive sectors, the time to act is now.


Sources:

Source: Original article


Attacks like those carried out by clusters UNC6293, UNC7005, and UNC5976 underscore how critical timely threat intelligence sharing is among organizations operating in the same sector. IsacChain enables the secure, verifiable exchange of indicators of compromise related to OAuth abuse and social engineering campaigns, while simultaneously supporting automated NIS2 compliance. Every piece of shared intelligence is tracked and certified through blockchain verification, guaranteeing the integrity and non-repudiation of data exchanged between ISAC members. Discover how IsacChain can help your organization at www.isacchain.com