Inhospitable: Tracking Russian Cyber Espionage Infrastructure

Inhospitable: Tracking Russian Cyber Espionage Infrastructure
Google Threat Intelligence Group research on Russian-aligned espionage clusters showed how infrastructure, registration data, CSS, favicon, and DNS pivots can reveal additional related domains used for phishing and decoy sites. The article highlights UNC6293, UNC7005, and UNC5976, along with lookalike domains and proxy infrastructure tied to OAuth phishing, device code phishing, and deceptive redirects. #UNC6293 #UNC7005 #UNC5976 #foreignrelationsus #stateaffairsus #verifydrivecom

Keypoints

  • GTIG published research on several Russian cyber espionage threat clusters targeting academia, think tanks, and other organizations in Europe and the United States.
  • UNC6293 used foreignrelations[.]us and dosportal[.]app as lures for OAuth phishing, and historical DNS/WHOIS data revealed additional related domains.
  • Some infrastructure showed copied content or proxying of legitimate sites, including Council on Foreign Relations references and lookalike pages for the U.S. Department of State and Washington Ballet.
  • CSS and favicon pivots linked additional domains and origin IPs, including Cloudflare-fronted lookalike infrastructure and multiple Google Drive-themed phishing domains.
  • UNC7005 was described as similar to UNC6293 but less sophisticated, using device code phishing against Microsoft and WhatsApp accounts.
  • UNC5976 used drive[.]google[.]verify-drive[.]com in an OAuth phishing campaign, and title/header/favicon pivots uncovered more related domains and IPs.
  • Registration-based pivots identified a small cluster of potentially related domains, though some were likely unrelated or only low-confidence leads.

MITRE Techniques

  • [T1566.002 ] Phishing: Spearphishing Link – Used lure domains and email links to direct victims to fake pages and credential-harvesting sites (‘facilitate OAuth phishing attacks’, ‘phishing through links in email’).
  • [T1528 ] Steal Application Access Token – OAuth phishing was used to obtain access through fake Microsoft/Google-style authorization flows (‘used the domain names foreignrelations[.]us and dosportal[.]app as a lure to facilitate OAuth phishing attacks’).
  • [T1078 ] Valid Accounts – Device code phishing targeted Microsoft and WhatsApp accounts by abusing legitimate authentication processes (‘device code phishing to target WhatsApp accounts’).
  • [T1056.002 ] GUI Input Capture: GUI Input Capture via Phishing Portal – Fake login prompts and invite pages were used to collect credentials and session data (‘displayed an “Ad Manager” login prompt’, ‘fake invite page was updated’).
  • [T1204.001 ] User Execution: Malicious Link – Victims were expected to click links in email and land on actor-controlled infrastructure (‘phishing through links in email’).
  • [T1189 ] Drive-by Compromise – Redirects to legitimate-looking pages and copied website content suggest users were led through deceptive web delivery (‘redirected visitors to official US Department of State websites’, ‘references the article’).

Indicators of Compromise

  • [Domain ] Actor-controlled or related lure domains – foreignrelations[.]us, dosportal[.]app, stateaffairs[.]us, the-washington-ballet[.]com, my-invite[.]org, verify-drive[.]com, and other related domains.
  • [Domain ] Additional related infrastructure from pivots – internationalaffairsportal[.]us, linkfileshare[.]net, fileshareapp[.]org, sharefolders[.]org, formshare[.]cloud, and other related domains.
  • [IP Address ] Likely origin or hosting infrastructure – 151.236.15[.]213, 185.158.250[.]155, 104.194.159[.]150, 93.127.160[.]28, and other tracked IPs.
  • [URL/Domain ] Redirect and phishing endpoints – ad-g[.]org/login and drive[.]google[.]verify-drive[.]com.
  • [Email Address ] Registrant and lure-related emails – given956[@]2200freefonts[.]com, registration[@]globsec[.]org.
  • [Hash ] Content and fingerprinting pivots – CSS class hash 6971626bf83b92c4ceef538c8919ca17, favicon MD5 c66f20f2e39eb2f6a0a4cdbe0d955e5f, and header hash e4c0a20a5e50632867cd.
  • [Registrar/NS Set ] Registration pivot data – OwnRegistrar, Inc. and name servers 5545.dns1.managedns.org, 5545.dns2.managedns.org, 5545.dns3.managedns.org, 5545.dns4.managedns.org.


Read more: https://www.validin.com/blog/inhospitable_russian_cyber_espionage_clusters/