Threats Tagged 'oauth phishing'
View all threats tagged with 'oauth phishing'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'oauth phishing'
Click on any threat for detailed analysis and mitigation recommendations
This analysis details infrastructure used by multiple Russian cyber espionage clusters targeting academia, think tanks, and organizations in Europe and the United States. The clusters UNC6293, UNC7005, and UNC5976 employ OAuth phishing, Microsoft device code phishing, and WhatsApp targeting techniques. UNC6293 uses sophisticated lure domains impersonating reputable organizations with possible Evilginx configurations. UNC7005 shows lower operational security with simpler phishing domains. UNC5976 uses Google Drive impersonation for OAuth phishing. The investigation uses DNS data, CSS hashes, favicon analysis, registration patterns, and certificate info to track and identify related malicious infrastructure. Join the discussion | AlienVault OTX General | 08/26/2026, 21:58:59 UTC Added: 08/27/2026, 22:07:26 UTC |
Three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—target individuals in academia, aerospace, defense, governments, and think tanks in Europe and the US. They use sophisticated phishing techniques including app password phishing, OAuth phishing, device code phishing, and malware deployment. UNC6293 and UNC7005 are linked with moderate confidence to ICE RELIC (APT29), while UNC5976 is distinct. Their operations involve social engineering tactics such as fake diplomatic invitations and conference registrations. They abuse legitimate authentication mechanisms like Google OAuth and Microsoft device codes, complicating detection. Join the discussion | AlienVault OTX General | 08/20/2026, 17:09:14 UTC Added: 08/20/2026, 23:22:26 UTC |
In collaboration with the International Consortium of Investigative Journalists (ICIJ), two distinct actor clusters aligned with the People's Republic of China were identified targeting journalists and civil society members. GLITTER CARP conducted widespread credential harvesting campaigns against Uyghur, Tibetan, Taiwanese, and Hong Kong diaspora activists, as well as journalists covering these communities, employing digital impersonation and fake security alerts while frequently reusing infrastructure. SEQUIN CARP specifically targeted journalists involved in ICIJ's China Targets investigation using sophisticated OAuth consent phishing attacks with well-developed personas based on co-opted narratives, though operational mistakes revealed poor persona management. Both campaigns demonstrate China's Military-Civil Fusion system leveraging private contractors to conduct digital transnational repression at scale, with targeting intensifying following the China Targets publication that exposed Chinese governme... Join the discussion | AlienVault OTX General | 04/28/2026, 07:09:29 UTC Added: 04/28/2026, 14:21:52 UTC |
Showing 1 to 3 of 3 results