Google Links Three Phishing Clusters to Russian Espionage

Google has tracked three suspected Russian espionage clusters targeting people in US and European government, defense and research sectors. One group allegedly used genuine login flows to request access codes or URLs.
Google Links Three Phishing Clusters to Russian Espionage
Share

Google Threat Intelligence Group says three suspected Russian cyber-espionage clusters targeted selected people in Europe and the United States, with campaigns still active in June 2026. The groups, tracked as UNC6293, UNC7005 and UNC5976, focused on people in academia, aerospace, defense, government agencies and think tanks.

Google personnel said the campaigns each involved fewer than 100 targets and that fewer than 10 victims had been confirmed, as cited by The Register. The operations date back to at least 2025 and have used phishing, OAuth abuse and malware deployment to seek account access.

UNC6293 used legitimate login steps to pressure targets

UNC6293 has impersonated US State Department employees while trying to gain access to email accounts. In June, Google observed the cluster asking targets for either a complete URL or a verification code after they had completed a genuine login, placing the malicious request after an authentication step that can appear familiar to the recipient.

Google has tracked UNC6293 for nearly two years. The company previously said the group sought application-specific passwords from people critical of Russia, indicating that its operators have repeatedly focused on credentials and account access rather than relying on a single phishing method.

The alleged APT29 link raises the stakes

Google associates UNC6293 with suspected threat actor APT29, also called Cozy Bear or Ice Relic. Government and private-sector researchers commonly connect APT29 to Russia’s Foreign Intelligence Service, and security analysts have linked it to the 2020 SolarWinds compromise. That history matters for the targeted sectors: aerospace, defense and government accounts can expose policy work, research and sensitive communications even when a campaign reaches relatively few people.

Available summaries leave several points unresolved. They do not identify the compromised organizations or individuals, give a combined victim total across all three clusters, establish that one Russian organization runs every group, or fully describe the technical details and impact of reported WhatsApp account-linking activity.

Riot Games to End 2XKO Active Development in December

Riot Games to End 2XKO Active Development in December

Prev
Riot Games Will End 2XKO Active Development in December 2026

Riot Games Will End 2XKO Active Development in December 2026

Next
Comments
Add a comment

Leave a Reply

Your email address will not be published. Required fields are marked *