highAPT

Suspected Russian APT Clusters Abusing Google OAuth and WhatsApp Device Linking for Account Takeover

First seen Aug 21, 2026 · Updated Aug 21, 2026

phishingoauth-abusecredential-theftsocial-engineeringrussiastate-sponsoredaccount-takeoverwhatsappgoogle-oauth

Three suspected Russian cyber espionage clusters (UNC6293, UNC7005, UNC5976) are abusing legitimate Google OAuth flows and WhatsApp device-linking features to hijack accounts of individuals in academia, aerospace/defense, government, and think tanks across Europe and the U.S. These campaigns rely on persistent, adaptive social engineering rather than exploiting software vulnerabilities, making them difficult to detect with traditional malware defenses.

Technical Analysis

The threat actors abuse legitimate authentication mechanisms—Google OAuth consent flows and WhatsApp's QR-code-based multi-device linking—to gain unauthorized access to victim accounts without deploying traditional malware, likely through phishing pages that trick targets into approving malicious OAuth grants or scanning attacker-controlled WhatsApp linking codes. This technique bypasses many endpoint and email security controls since it exploits trust in legitimate service infrastructure (accounts.google.com, web.whatsapp.com) rather than delivering payloads. The targeting of high-value individuals in academia, defense, and government think tanks suggests an intelligence-gathering objective consistent with Russian state-sponsored espionage operations. Organizations using AI agents or LLM-based assistants that are granted OAuth access to Google Workspace, Gmail, or Drive for tool use and RAG data ingestion could have those API tokens and connected credentials hijacked via the same OAuth-abuse technique, giving attackers persistent access to agent-connected data sources and downstream systems.

Affected Systems

Google Workspace/Gmail accounts using OAuth-based third-party app authorization; WhatsApp accounts with multi-device linking enabled; individual user accounts at academic, aerospace/defense, government, and think tank organizations in Europe and the U.S.

Indicators of Compromise

  • UNC6293 (threat cluster identifier)
  • UNC7005 (threat cluster identifier)
  • UNC5976 (threat cluster identifier)
  • No specific hashes, IPs, or domains disclosed in source reporting

Remediation Steps

  1. 1

    Audit OAuth app permissions

    Review and revoke unnecessary or unrecognized third-party OAuth grants on Google Workspace and personal Google accounts, especially for high-risk personnel.

  2. 2

    Restrict WhatsApp device linking

    Educate users on verifying QR codes before linking devices and monitor for unauthorized linked devices in WhatsApp settings.

  3. 3

    Enforce phishing-resistant MFA

    Deploy FIDO2/WebAuthn hardware security keys for high-value accounts to reduce susceptibility to consent-phishing and session hijacking.

  4. 4

    Monitor OAuth grant anomalies

    Enable Google Workspace admin alerts for new third-party app authorizations and review logs for suspicious consent grants.

  5. 5

    Audit agent and integration OAuth scopes

    For organizations running AI agents or automation tools with OAuth access to Google services, review granted scopes, rotate tokens, and restrict agent permissions to least privilege.

  6. 6

    Security awareness training

    Train personnel in targeted sectors (academia, defense, government, think tanks) to recognize consent-phishing and social engineering tied to authentication flows.

Industries Most Exposed

academiaaerospace and defensegovernmentthink tanksresearch institutions

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.