Google Threat Intelligence Group (GTIG) has identified two distinct suspected Russian cyber espionage clusters—UNC6293 and UNC7005—that are abusing legitimate authentication flows to target high-value individuals. These operations focus specifically on compromising accounts within academia, aerospace/defense sectors, governments, think tanks in Europe, and US-based research institutions.
What Changed: The Shift from Exploits to Social Engineering
The primary shift observed is the move away from purely technical exploitation toward sophisticated social engineering that targets human behavior. UNC6293 has evolved its tactics over time; while initially relying on app password phishing, it now incorporates OAuth flows into its repertoire.
Authentication Architecture Implications
The core mechanism involves the abuse of legitimate authentication workflows to compromise accounts without triggering immediate suspicion from users. This presents a specific challenge for identity and access management (IAM) architectures:
- App Password Phishing: Attackers convince targets to set unique app passwords on their own behalf, granting attackers direct account access bypassing standard two-factor authentication checks.
- OAuth Token Exchange Abuse: Victims are tricked into sharing verification codes or full URLs after a legitimate login. By providing these credentials, the victim effectively grants upstream authorization for downstream service access to an attacker-controlled entity.
This distinction is critical: application-layer filtering and prompt rules cannot substitute for proper IAM/RBAC controls if users are socially engineered into bypassing them voluntarily.
Operational Considerations for Platform Teams
Platform teams must recognize that these campaigns often impersonate legitimate organizations, such as the US State Department or specific forums like GLOBSEC. The infrastructure used by UNC7005 shows divergent characteristics compared to other clusters but shares high-level similarities with ICE RELIC (formerly APT29).
Because operations are highly selective—often targeting fewer than five users at a time—the volume of traffic may not trigger standard anomaly detection thresholds. However, the persistence and adaptability suggest that these groups will continue to refine their social engineering tactics.
What This Means For Practitioners
To mitigate risk from UNC6293 and UNC7005 operations:
- Elevate User Awareness Training: Educate users on the specific mechanics of app password phishing, where attackers request unique passcodes for "secure" apps or devices.
The goal is to ensure that targets can recognize malicious outreach even when it mimics legitimate authentication flows. For Google Cloud environments specifically, practitioners should review their OAuth consent screens and monitoring capabilities related to external provider logins.
Google Cloud users must verify that verification code requests are not being fulfilled by unverified third parties.

