Live
From App‑Level LLMs to a Shared Platform: Redesigning the Stack to Tame HallucinationsFrom Ad‑hoc Checks to a Production‑Ready Agent Evaluation FrameworkReal‑Time Observability for Claude Code Sessions with the Statuspane ModEnforcing US Data Residency with Cloudflare D1AI agents CI: why repository‑centric pipelines are breakingAI Agent Inbox: Deploy Pizza Bot for Background Task ExecutionOpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturersFrom App‑Level LLMs to a Shared Platform: Redesigning the Stack to Tame HallucinationsFrom Ad‑hoc Checks to a Production‑Ready Agent Evaluation FrameworkReal‑Time Observability for Claude Code Sessions with the Statuspane ModEnforcing US Data Residency with Cloudflare D1AI agents CI: why repository‑centric pipelines are breakingAI Agent Inbox: Deploy Pizza Bot for Background Task ExecutionOpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturers
Google Cloud

Russian Clusters Exploit OAuth Flows to Target Critical Infrastructure

AI SummaryPowered by AI

New threat clusters UNC7005 and UNC6293 are leveraging legitimate authentication workflows, including app passwords and device codes, to compromise accounts of individuals in academia, defense, and government sectors. Security engineers must update their identity monitoring strategies because these attacks rely on social engineering rather than traditional exploit chains.

Google Threat Intelligence Group (GTIG) has identified two distinct suspected Russian cyber espionage clusters—UNC6293 and UNC7005—that are abusing legitimate authentication flows to target high-value individuals. These operations focus specifically on compromising accounts within academia, aerospace/defense sectors, governments, think tanks in Europe, and US-based research institutions.

What Changed: The Shift from Exploits to Social Engineering

The primary shift observed is the move away from purely technical exploitation toward sophisticated social engineering that targets human behavior. UNC6293 has evolved its tactics over time; while initially relying on app password phishing, it now incorporates OAuth flows into its repertoire.

Authentication Architecture Implications

The core mechanism involves the abuse of legitimate authentication workflows to compromise accounts without triggering immediate suspicion from users. This presents a specific challenge for identity and access management (IAM) architectures:

  • App Password Phishing: Attackers convince targets to set unique app passwords on their own behalf, granting attackers direct account access bypassing standard two-factor authentication checks.
  • OAuth Token Exchange Abuse: Victims are tricked into sharing verification codes or full URLs after a legitimate login. By providing these credentials, the victim effectively grants upstream authorization for downstream service access to an attacker-controlled entity.

This distinction is critical: application-layer filtering and prompt rules cannot substitute for proper IAM/RBAC controls if users are socially engineered into bypassing them voluntarily.

Operational Considerations for Platform Teams

Platform teams must recognize that these campaigns often impersonate legitimate organizations, such as the US State Department or specific forums like GLOBSEC. The infrastructure used by UNC7005 shows divergent characteristics compared to other clusters but shares high-level similarities with ICE RELIC (formerly APT29).

Because operations are highly selective—often targeting fewer than five users at a time—the volume of traffic may not trigger standard anomaly detection thresholds. However, the persistence and adaptability suggest that these groups will continue to refine their social engineering tactics.

What This Means For Practitioners

To mitigate risk from UNC6293 and UNC7005 operations:

  • Elevate User Awareness Training: Educate users on the specific mechanics of app password phishing, where attackers request unique passcodes for "secure" apps or devices.

The goal is to ensure that targets can recognize malicious outreach even when it mimics legitimate authentication flows. For Google Cloud environments specifically, practitioners should review their OAuth consent screens and monitoring capabilities related to external provider logins.
Google Cloud users must verify that verification code requests are not being fulfilled by unverified third parties.

  • Audit App Password Policies: Review policies regarding the issuance of app passwords, as these provide a direct bypass for 2FA if compromised via social engineering.
  • Originally published atGoogle Cloud Blog