Google Threat Intelligence Group says three suspected Russian cyber-espionage clusters targeted selected people in Europe and the United States, with campaigns still active in June 2026. The groups, tracked as UNC6293, UNC7005 and UNC5976, focused on people in academia, aerospace, defense, government agencies and think tanks.
Google personnel said the campaigns each involved fewer than 100 targets and that fewer than 10 victims had been confirmed, as cited by The Register. The operations date back to at least 2025 and have used phishing, OAuth abuse and malware deployment to seek account access.
UNC6293 used legitimate login steps to pressure targets
UNC6293 has impersonated US State Department employees while trying to gain access to email accounts. In June, Google observed the cluster asking targets for either a complete URL or a verification code after they had completed a genuine login, placing the malicious request after an authentication step that can appear familiar to the recipient.
Google has tracked UNC6293 for nearly two years. The company previously said the group sought application-specific passwords from people critical of Russia, indicating that its operators have repeatedly focused on credentials and account access rather than relying on a single phishing method.
The alleged APT29 link raises the stakes
Google associates UNC6293 with suspected threat actor APT29, also called Cozy Bear or Ice Relic. Government and private-sector researchers commonly connect APT29 to Russia’s Foreign Intelligence Service, and security analysts have linked it to the 2020 SolarWinds compromise. That history matters for the targeted sectors: aerospace, defense and government accounts can expose policy work, research and sensitive communications even when a campaign reaches relatively few people.
Available summaries leave several points unresolved. They do not identify the compromised organizations or individuals, give a combined victim total across all three clusters, establish that one Russian organization runs every group, or fully describe the technical details and impact of reported WhatsApp account-linking activity.