Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia
Summary
Google Threat Intelligence is tracking three suspected Russian cyber espionage groups (UNC6293, UNC7005, and UNC5976) that target academics, government officials, and think tank workers by abusing legitimate authentication flows (the standard login systems most websites use). These groups use phishing (deceptive emails designed to steal credentials) and social engineering (psychological manipulation tactics) to trick targets into revealing app passwords (less secure access codes that bypass two-factor authentication, a secondary security check) or OAuth verification codes (tokens that grant access to accounts), rather than stealing passwords directly.
Classification
Original source: https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia/
First tracked: August 20, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%