Skip to main content

Distinct Clusters Target Individuals of Interest to Russia

0
Medium
Published: 08/20/2026 (08/20/2026, 17:09:14 UTC)
Source: AlienVault OTX General

Description

Three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—target individuals in academia, aerospace, defense, governments, and think tanks in Europe and the US. They use sophisticated phishing techniques including app password phishing, OAuth phishing, device code phishing, and malware deployment. UNC6293 and UNC7005 are linked with moderate confidence to ICE RELIC (APT29), while UNC5976 is distinct. Their operations involve social engineering tactics such as fake diplomatic invitations and conference registrations. They abuse legitimate authentication mechanisms like Google OAuth and Microsoft device codes, complicating detection.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 03:33:31 UTC

Technical Analysis

This threat involves three distinct Russian cyber espionage clusters abusing legitimate authentication flows to compromise targeted individuals of interest primarily in Europe and the United States. The clusters—UNC6293, UNC7005, and UNC5976—conduct advanced phishing campaigns leveraging app password phishing, OAuth phishing, device code phishing, and malware deployment including MaaS infostealers like VIDAR and ATOMIC. UNC6293 and UNC7005 are assessed with moderate confidence as initial access clusters linked to ICE RELIC (formerly APT29), while UNC5976 appears unrelated. Their social engineering techniques include fake diplomatic invitations, conference registrations, and hospitality captive portal redirects. They exploit legitimate authentication mechanisms such as Google OAuth, Microsoft device codes, and WhatsApp device linking to compromise personal accounts, making detection and mitigation challenging.

Potential Impact

The threat actors gain unauthorized access to personal and organizational accounts by abusing legitimate authentication mechanisms and deploying malware, enabling espionage activities targeting sensitive sectors such as academia, aerospace, defense, government, and think tanks. This can lead to data exfiltration, credential theft, and prolonged undetected access, impacting confidentiality and operational security of targeted entities.

Defensive Guidance

No official patch or fix applies as this is a threat actor campaign abusing legitimate authentication flows. Organizations should enhance phishing detection capabilities, educate users on sophisticated social engineering tactics, and monitor for suspicious OAuth and device code authorization activities. Multi-factor authentication and anomaly detection on authentication flows can help mitigate risk. Since no vendor advisory or patch is available, continuous vigilance and user awareness are critical.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia"]
Adversary
APT29
Pulse Id
6a8734bac622f3c7b2d9a633

Indicators of Compromise

Domain

ValueDescriptionCopy
domainmioisiskwowiwjowuwjwolab.club
—
domainmiov2iaiaoubqosiqoiajwowiwjso.online
—
domainchamber-ua.org
—
domainfewfwfwfwfwf.info
—
domainglobsec.net
—
domainwa-connect.net
—
domainm365-owa.com
—
domainms365-device.com
—
domainms365-live.com
—
domainowa-ms365.com
—
domainmy-invite.org
—
domainwa-connect.eu
—
domainwa-meeting.com
—
domainstatistic-ms.live
—
domainfinishoperations.com
—
domainfinishoperations.org
—
domainfoc-share.com
—
domainfoc-share.org
—
domainforeignrelations.us
—
domaininternal-share.com
—
domainshare-foc.com
—
domainshopinvite.org
—
domainverify-drive.com
—
domainwa-device.com
—
domainwa-invite.com
—
domaindrive.google.verify-drive.com
—
domainmail.kiis.co.uk
—

Hash

ValueDescriptionCopy
hashbe99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c
—
hashc6f4df18cb880500f3921a179c3a3766
—
hash937e75e0e1c82eecab69e9b8ad481bd7e0845308
—
hash1e3ee845fde739fcd3ca9ce62c7f142a7c501d11db4c4fb294d4939f12d0f916
—
hash5484009071ea96c7b43e8fa052b8d88a
—
hash1b97e0df9600335b0cd8db2eb4577d3dbf6e76db
—
hash125752ad7c20d715920a3b2fb0fdde660f07b3f2b053665cf38c2d6d9de86e1e
—
hash1d9299799a7b8da67c44ebec064d64542c27645f8e84de4a22ca3f6cbc843e3c
—
hash20e20b074967ed6f6e04d609ccec5ff7492665ef25f894c90c2ddc92fa47ac38
—
hash28f622028e690c943f7fa9aca426c07cab52b5aaba757ef8a3328609c0b3bec3
—
hash2c7f4165967d6f7737b3fef87959846920b57a5368b531ad1427c7214d4c41a2
—
hash403b624e35777cbc07dbe66398b21bba70396a20b859c880732338ce1dd1f41f
—
hash5b8d50c2e8cc3038b7c6e6dbf1219f6e814930a1e3c0053143a1191ae67f8ffc
—
hash6f7090895c1c3dee30de6b3f098ca3a788dc198646e5293a8b1210430b0add97
—
hasha06a8fd1b6fa1924199a4540cf16d089217ce8f78c617739946f145fd1fc88c1
—
hashc5826032207d623a7f6caec8465af7364eccc355f9a48897da2a54f3e4420265
—
hashca3be5885afb3eb3bb19341e2653212200c568f3f900e0b2f04de9ba209aed25
—

Threat ID: 6a878c32acd9273b494430ae

Added to database: 08/20/2026, 23:22:26 UTC

Last enriched: 09/11/2026, 03:33:31 UTC

Last updated: 10/04/2026, 06:49:34 UTC

Views: 146

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses