Google Threat Intelligence Group detailed three suspected Russian espionage clusters—UNC6293, UNC7005, and UNC5976—that abuse legitimate authentication flows such as app passwords, device code linking, OAuth, and messaging-app linking to steal access across academia, defense, governments, and think tanks. The report also ties UNC7005 to malware delivery and infrastructure overlaps involving VIDAR, ATOMIC, ENGINELIGHT, CHERRYPIE, and HEADRUSH, while connecting UNC6293 and UNC7005 to ICE RELIC. #UNC6293 #UNC7005 #UNC5976 #ICE_RELIC #VIDAR #ATOMIC #ENGINELIGHT #CHERRYPIE #HEADRUSH
Keypoints
- GTIG tracks three suspected Russian cyber espionage clusters: UNC6293, UNC7005, and UNC5976.
- UNC6293 is assessed as a subcluster of ICE RELIC and has focused on app password phishing and later OAuth phishing.
- UNC7005, also tied to ICE RELIC, uses app password phishing, Microsoft and WhatsApp device linking, OAuth phishing, and malware delivery.
- UNC7005 leveraged captive portal redirects from hotel and conference networks to steer victims to attacker-controlled login pages.
- UNC5976 uses OAuth phishing, cloud projects, and a malicious Excel plugin named HEADRUSH to collect authentication tokens and deliver malware.
- The campaign targeted academia, aerospace, defense, governments, think tanks, diplomats, nonprofits, and researchers across Europe and the United States.
- GTIG recommends stronger account protections, app password removal, device auditing, and caution with suspicious invitations or authentication prompts.
MITRE Techniques
- [T1566.002 ] Phishing: Spearphishing Link – Used to lure targets to attacker-controlled pages for authentication theft and malware delivery (‘sent targeted phishing emails linking to an attacker-controlled domain’).
- [T1056 ] Input Capture – Used when victims were prompted to enter app passwords, verification codes, phone numbers, or credentials into fake login forms (‘enter it into an authentication form on an otherwise legitimate looking website’).
- [T1606 ] Forge Web Credentials – Used by inducing victims to provide app passwords, OAuth verification codes, and login artifacts that grant access (‘providing the requested verification code the target would grant UNC6293 access to the account’).
- [T1528 ] Steal Application Access Token – Used in OAuth phishing to capture tokens from redirected cloud projects (‘used to steal authentication tokens that grant the attacker access to the target account’).
- [T1133 ] External Remote Services – Abused legitimate authentication services such as Google OAuth, Microsoft login, and WhatsApp device linking to gain account access (‘abuse legitimate authentication workflows to compromise accounts’).
- [T1027 ] Obfuscated Files or Information – Used with an obfuscated Go binary for VIDAR to hinder analysis (‘This sample is an obfuscated Go binary’).
- [T1497.001 ] Virtualization/Sandbox Evasion: System Checks – Used browser fingerprinting and webdriver checks to detect automated analysis (‘attempt to detect and evade automated analysis efforts’).
- [T1021 ] Remote Services – Used legitimate cloud and messaging workflows to access and control victim accounts (‘link their WhatsApp accounts with an attacker controlled device’).
- [T1119 ] Automated Collection – Used cloud scripts to automatically retrieve authentication tokens from URLs (‘retrieve the authentication token from the URL and save it for the operator to later retrieve’).
- [T1204.002 ] User Execution: Malicious File – Used social engineering to make targets download and run “Summit Companion App,” delivered as infostealer payloads (‘clicked the button to download a “Summit Companion App”’).
- [T1059.001 ] Command and Scripting Interpreter: PowerShell – Referenced through the malicious PowerShell infostealer CHERRYPIE (‘CHERRYPIE PowerShell infostealer’).
- [T1105 ] Ingress Tool Transfer – Delivered malware samples and payloads through phishing pages and downloads (‘served a sample of VIDAR to the target’).
- [T1057 ] Process Discovery – Not directly explicit, but implied by system fingerprinting and environment checks before serving payloads (‘the target’s system is fingerprinted’).
Indicators of Compromise
- [Domains ] phishing and attacker infrastructure domains – dosportal.app, foreignrelations.us, and other phishing domains such as wa-connect.eu and owa-ms365.com
- [IP addresses ] C2 and related infrastructure – 107.189.18.7, 104.194.159.150, and other related IPs such as 31.57.243.154
- [SHA256 hashes ] malware and lure files – 1d9299799a7b8da67c44ebec064d64542c27645f8e84de4a22ca3f6cbc843e3c, c5826032207d623a7f6caec8465af7364eccc355f9a48897da2a54f3e4420265, and 2c7f4165967d6f7737b3fef87959846920b57a5368b531ad1427c7214d4c41a2
- [File names / malware names ] payloads and tools – VIDAR, ATOMIC, ENGINELIGHT, CHERRYPIE, and HEADRUSH
- [Email addresses ] attacker infrastructure registration and delivery – [email protected], [email protected], and [email protected]
- [URLs / paths ] phishing and C2 endpoints – drive.google.verify-drive.com, /api/code//recording, and /chat/login