Distinct Clusters Target Individuals of Interest to Russia
Description
Three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—target individuals in academia, aerospace, defense, governments, and think tanks in Europe and the US. They use sophisticated phishing techniques including app password phishing, OAuth phishing, device code phishing, and malware deployment. UNC6293 and UNC7005 are linked with moderate confidence to ICE RELIC (APT29), while UNC5976 is distinct. Their operations involve social engineering tactics such as fake diplomatic invitations and conference registrations. They abuse legitimate authentication mechanisms like Google OAuth and Microsoft device codes, complicating detection.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves three distinct Russian cyber espionage clusters abusing legitimate authentication flows to compromise targeted individuals of interest primarily in Europe and the United States. The clusters—UNC6293, UNC7005, and UNC5976—conduct advanced phishing campaigns leveraging app password phishing, OAuth phishing, device code phishing, and malware deployment including MaaS infostealers like VIDAR and ATOMIC. UNC6293 and UNC7005 are assessed with moderate confidence as initial access clusters linked to ICE RELIC (formerly APT29), while UNC5976 appears unrelated. Their social engineering techniques include fake diplomatic invitations, conference registrations, and hospitality captive portal redirects. They exploit legitimate authentication mechanisms such as Google OAuth, Microsoft device codes, and WhatsApp device linking to compromise personal accounts, making detection and mitigation challenging.
Potential Impact
The threat actors gain unauthorized access to personal and organizational accounts by abusing legitimate authentication mechanisms and deploying malware, enabling espionage activities targeting sensitive sectors such as academia, aerospace, defense, government, and think tanks. This can lead to data exfiltration, credential theft, and prolonged undetected access, impacting confidentiality and operational security of targeted entities.
Defensive Guidance
No official patch or fix applies as this is a threat actor campaign abusing legitimate authentication flows. Organizations should enhance phishing detection capabilities, educate users on sophisticated social engineering tactics, and monitor for suspicious OAuth and device code authorization activities. Multi-factor authentication and anomaly detection on authentication flows can help mitigate risk. Since no vendor advisory or patch is available, continuous vigilance and user awareness are critical.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia"]
- Adversary
- APT29
- Pulse Id
- 6a8734bac622f3c7b2d9a633
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainmioisiskwowiwjowuwjwolab.club | — | |
domainmiov2iaiaoubqosiqoiajwowiwjso.online | — | |
domainchamber-ua.org | — | |
domainfewfwfwfwfwf.info | — | |
domainglobsec.net | — | |
domainwa-connect.net | — | |
domainm365-owa.com | — | |
domainms365-device.com | — | |
domainms365-live.com | — | |
domainowa-ms365.com | — | |
domainmy-invite.org | — | |
domainwa-connect.eu | — | |
domainwa-meeting.com | — | |
domainstatistic-ms.live | — | |
domainfinishoperations.com | — | |
domainfinishoperations.org | — | |
domainfoc-share.com | — | |
domainfoc-share.org | — | |
domainforeignrelations.us | — | |
domaininternal-share.com | — | |
domainshare-foc.com | — | |
domainshopinvite.org | — | |
domainverify-drive.com | — | |
domainwa-device.com | — | |
domainwa-invite.com | — | |
domaindrive.google.verify-drive.com | — | |
domainmail.kiis.co.uk | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashbe99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c | — | |
hashc6f4df18cb880500f3921a179c3a3766 | — | |
hash937e75e0e1c82eecab69e9b8ad481bd7e0845308 | — | |
hash1e3ee845fde739fcd3ca9ce62c7f142a7c501d11db4c4fb294d4939f12d0f916 | — | |
hash5484009071ea96c7b43e8fa052b8d88a | — | |
hash1b97e0df9600335b0cd8db2eb4577d3dbf6e76db | — | |
hash125752ad7c20d715920a3b2fb0fdde660f07b3f2b053665cf38c2d6d9de86e1e | — | |
hash1d9299799a7b8da67c44ebec064d64542c27645f8e84de4a22ca3f6cbc843e3c | — | |
hash20e20b074967ed6f6e04d609ccec5ff7492665ef25f894c90c2ddc92fa47ac38 | — | |
hash28f622028e690c943f7fa9aca426c07cab52b5aaba757ef8a3328609c0b3bec3 | — | |
hash2c7f4165967d6f7737b3fef87959846920b57a5368b531ad1427c7214d4c41a2 | — | |
hash403b624e35777cbc07dbe66398b21bba70396a20b859c880732338ce1dd1f41f | — | |
hash5b8d50c2e8cc3038b7c6e6dbf1219f6e814930a1e3c0053143a1191ae67f8ffc | — | |
hash6f7090895c1c3dee30de6b3f098ca3a788dc198646e5293a8b1210430b0add97 | — | |
hasha06a8fd1b6fa1924199a4540cf16d089217ce8f78c617739946f145fd1fc88c1 | — | |
hashc5826032207d623a7f6caec8465af7364eccc355f9a48897da2a54f3e4420265 | — | |
hashca3be5885afb3eb3bb19341e2653212200c568f3f900e0b2f04de9ba209aed25 | — |
Threat ID: 6a878c32acd9273b494430ae
Added to database: 08/20/2026, 23:22:26 UTC
Last enriched: 09/11/2026, 03:33:31 UTC
Last updated: 10/04/2026, 06:49:34 UTC
Views: 146
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.