← Back to blog

Russian Hackers Exploit OAuth Flows to Target Defense and Academic Sectors

Three Russian threat groups are abusing legitimate authentication mechanisms like Google OAuth and WhatsApp linking to hijack accounts. Targets include aerospace, defense, government, and academic institutions in Europe and the U.S.

TL;DR

  • Three Russian clusters (UNC6293, UNC7005, UNC5976) exploited OAuth and messaging app linking features.
  • Targets span academia, aerospace, defense, government, and think tanks across Europe and the U.S.
  • Attackers used legitimate authentication flows to bypass traditional security controls.
  • The campaign highlights risks of third-party identity providers in enterprise environments.
  • Organizations should review OAuth app permissions and implement adaptive authentication measures.

Cybersecurity researchers have uncovered a sophisticated campaign by three suspected Russian threat actors leveraging legitimate authentication protocols to compromise high-value targets. These groups—designated as UNC6293, UNC7005, and UNC5976—are specifically targeting professionals in academia, aerospace, defense, government agencies, and think tanks across Europe and the United States.

Rather than exploiting technical vulnerabilities, these attackers are manipulating trusted identity verification processes such as Google OAuth and WhatsApp account linking. This approach allows them to gain unauthorized access while appearing as legitimate users, making detection significantly more challenging for defenders.

How the Attack Works

  • Attackers initiate OAuth flows through seemingly legitimate services to obtain user credentials.
  • They abuse WhatsApp linking features to establish backdoor communication channels.
  • Victims are often targeted via spear-phishing or social engineering tactics that lead to credential harvesting pages mimicking trusted services.
  • Once authenticated, attackers can maintain persistence without triggering standard alert systems.

Defensive Recommendations

  • Audit and restrict third-party OAuth applications with access to corporate accounts.
  • Implement conditional access policies that limit authentication from unexpected locations or devices.
  • Monitor for unusual patterns in identity provider logs, including repeated authorization attempts.
  • Educate staff on identifying malicious OAuth consent requests and suspicious linking prompts.
  • Use multi-factor authentication with hardware keys where possible to reduce risk of session hijacking.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Russian Hackers Exploit OAuth Flows to Target Defense and Academic Sectors — Agent Breach Blog | Agent Breach