Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US — Threadlinqs Intelligence
As of 2026-08-21, Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US is a high-severity apt threat attributed to APT29 (Ice Relic (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 43 indicators of compromise.
Threat ID: TL-2026-2091 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: APT29 (Ice Relic · Russia · ESPIONAGE
Google Threat Intelligence Group tracks three distinct suspected Russian cyberespionage clusters — UNC6293, UNC7005, and UNC5976 — conducting targeted phishing campaigns against individuals in
Since at least mid-2025, three suspected Russian state-sponsored threat clusters have been conducting targeted phishing operations against individuals of interest to the Kremlin across academia, aerospace, defense, government, think tanks, and NGOs in Europe, Ukraine, and the United States. The operations are characterized by increasing sophistication in the abuse of legitimate authentication flows, including OAuth token theft, application-specific password (ASP) phishing, device-code phishing, and WhatsApp device linking.
UNC6293 (moderate confidence: ICE RELIC/APT29 subcluster) operates small-scale campaigns targeting fewer than five individuals at a time, primarily critics of Russia. The cluster impersonates US State Department officials and has evolved from ASP phishing (June 2025) to OAuth phishing (June 2026), where victims are tricked into sharing verification codes from legitimate login sessions. Infrastructure includes phishing domains dosportal.app and foreignrelations.us, with commercial residential proxies used for post-compromise activity.
UNC7005 (also tracked as STORM-2945 by Microsoft; moderate confidence: ICE RELIC/APT29 subcluster) demonstrates the broadest and most technically diverse toolkit. First identified in February 2026, the cluster targets academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the US. Key TTPs include: (1) ASP phishing with target-unique app passwords; (2) Microsoft device-code phishing using spoofed event registration pages (GLOBSEC forum, embassy invites) with browser fingerprinting and headless browser detection for evasion; (3) WhatsApp device linking phishing (May-June 2026) where victims are lured into linking attacker-controlled devices and subsequently prompted to join fake voice calls that trigger malicious JavaScript recording audio/video via getUserMedia; (4) commodity infostealer delivery via MaaS (VIDAR for Windows, ATOMIC/AtomicStealer for macOS) distributed through spoofed summit companion app downloads; (5) OAuth phishing via cloud projects (August 2026) using domains spoofing the Finnish Operations Center (FOC); and (6) the CaptiveCrunch campaign (July 2026) — DNS poisoning of hotel and conference center captive portal Wi-Fi networks to redirect travelers to attacker-controlled infrastructure for adversary-in-the-middle credential theft and malware delivery.
UNC5976 (distinct suspected Russian intelligence service, not linked to ICE RELIC) targets military, aerospace, defense industrial base, and NGOs/think tanks primarily in Ukraine and Armenia. The cluster has been active since March 2026, conducting OAuth phishing via fake file-sharing websites that redirect victims through legitimate Google OAuth to attacker-controlled Google Cloud projects that harvest authentication tokens. UNC5976 also deploys HEADRUSH, a malicious Excel plugin that ultimately delivers an HTA downloader, distributed via a domain impersonating a Ukrainian research institute. The cluster has created at least 12 domains since March 2026 and is migrating away from Google infrastructure to other providers following Google's disruption efforts.
Microsoft's investigation of the CaptiveCrunch campaign revealed a sophisticated supply chain dimension: the compromises spanned multiple venues using common equipment and management systems, suggesting access to shared services within the captive portal ecosystem rather than isolated venue compromises. The campaign deployed CornFlake RAT (a full-featured Go-based Windows implant with ECDH P-256 encrypted C2, keylogging, audio/video surveillance, credential theft via ChromeKatz, and remote shell) and ChocoShell/CHERRYPIE (a PowerShell infostealer with AMSI bypass, UAC bypass chain, and CDP-based browser credential extraction that bypasses Chrome App-Bound Encryption). The ChocoShell script shows artifacts suggesting LLM-augmented development.
The campaigns are assessed by GTIG with high confidence as having a Russian nexus, bas
Target sectors: academia, aerospace, defense, government administration, think tanks, ngos, nonprofit, diplomatic, financial services, health, energy, legal
Target regions: ukraine, united states of america, 155 - Western Europe, 151 - Eastern Europe, armenia, india, saudi arabia
Timeline
- Citizen Lab publishes 'Same Sea, New Phish' report detailing UNC6293 ASP phishing campaign targeting Keir Giles, a prominent Russia expert. Attackers impersonate US State Department official and trick target into creating app-specific passwords, bypassing MFA.
- Google Threat Intelligence publishes 'What's in an ASP?' documenting UNC6293 campaigns using app-specific passwords named 'ms.state.gov' targeting academics and critics of Russia.
- UNC6293 evolves ASP phishing delivery: victims now enter app password into an authentication form on a legitimate-looking website rather than sharing via email. PDF lure documents retain same screenshots from June 2025 campaign.
- Volexity documents UNC6293 activity involving spoofed European security events for phishing campaigns.
- UNC7005 first identified by Google Threat Intelligence. Cluster begins app password phishing operations with target-unique app passwords referencing specific social engineering themes.
- UNC5976 OAuth phishing activity tracking begins. Cluster purchases file-sharing-themed domains and creates cloud projects to harvest OAuth authentication tokens.
- UNC7005 conducts device code phishing campaign spoofing GLOBSEC forum. Registration page includes epicurean wine selection theme — a recurring ICE RELIC phishing hallmark. Domain my-invite.org resolves to 104.194.159.150.
- UNC5976 deploys HEADRUSH malicious Excel plugin (SHA256: 2c7f4165967d6f7737b3fef87959846920b57a5368b531ad1427c7214d4c41a2) via domain impersonating a Ukrainian research institute. Ultimately delivers HTA downloader.
- UNC7005 conducts limited ENGINELIGHT Go malware phishing operation from bounce@chamber-ua.org with WhatsApp-spoofing domain wa-connect.eu. C2: statistic-ms.live.
- Microsoft observes Storm-2945 (UNC7005) manipulating DNS/HTTP traffic through hospitality captive portal networks. CaptiveCrunch campaign begins.
- UNC7005 retools GLOBSEC phishing page within days, adding browser fingerprinting and headless browser detection evasion scripts after 'embassy security policy' artifact error in original template.
- UNC7005 launches broader MaaS phishing wave targeting prominent US-based academics, diplomats, and researchers focused on Russia/former Soviet states. Delivers VIDAR (Windows) and ATOMIC/AMOS (macOS) infostealers via spoofed summit companion app.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 43 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1566.001, T1566.002, T1078, T1204.002, T1204.001, T1059.001, T1059.007, T1098.005, T1543.003, T1053.005