Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Executive Summary

Three Russian threat clusters—UNC6293, UNC7005, and UNC5976—have been observed exploiting legitimate Google OAuth and WhatsApp linking flows to target individuals in academia, aerospace, defense, governments, and think tanks across Europe and the U.S. The groups employ persistent, adaptive techniques to hijack accounts and facilitate espionage activities.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-20T19:59:19+00:00 - Category: threat-intel

Original Description: Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

"Great talent finds happiness in execution."

— Johann Wolfgang von Goethe
Source: The Hacker News