Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US

Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 (TL-2026-2091), also tracked as CaptiveCrunch, is a high-severity advanced persistent threat campaign, first published 2026-08-21. It is attributed to APT29 (Russia) with high confidence, affects Google Google Workspace, maps to 25 MITRE ATT&CK techniques (T1027, T1053.005, T1056.001), and is covered by 9 detection rules and 43 indicators of compromise.

Key facts for TL-2026-2091

Threat ID
TL-2026-2091
Also known as
CaptiveCrunch, STORM-2945, Same Sea, New Phish
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-08-21
Last reviewed
2026-08-21
Attribution
APT29
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
academia, aerospace, defense, government administration, think tanks, ngos, nonprofit, diplomatic, financial services, health, energy, legal
Target regions
ukraine, united states of america, 155 - Western Europe, 151 - Eastern Europe, armenia, india, saudi arabia
Detection rules
9
Indicators of compromise
43

Malware and tooling in Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976

Malware and tooling: AMOS, Vidar

Google Threat Intelligence Group tracks three distinct suspected Russian cyberespionage clusters — UNC6293, UNC7005, and UNC5976 — conducting targeted phishing campaigns against individuals in academia, aerospace, defense, government, and think tanks across Europe, Ukraine, and the US. UNC6293 and UNC7005 are linked to APT29 (Ice Relic / SVR) with moderate confidence, while UNC5976 is assessed as a distinct Russian intelligence service operation. The threat clusters abuse legitimate authentication flows — including OAuth token theft, application-specific password (ASP) phishing, device-code phishing, and WhatsApp device linking — and deliver commodity infostealers (VIDAR, ATOMIC/AMOS) and custom malware (CornFlake RAT, ChocoShell, ENGINELIGHT, HEADRUSH) via fake event registration pages, captive portal DNS poisoning at hotels and conference centers, and spoofed file-sharing portals.

How Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 works

Since at least mid-2025, three suspected Russian state-sponsored threat clusters have been conducting targeted phishing operations against individuals of interest to the Kremlin across academia, aerospace, defense, government, think tanks, and NGOs in Europe, Ukraine, and the United States. The operations are characterized by increasing sophistication in the abuse of legitimate authentication flows, including OAuth token theft, application-specific password (ASP) phishing, device-code phishing, and WhatsApp device linking.

UNC6293 (moderate confidence: ICE RELIC/APT29 subcluster) operates small-scale campaigns targeting fewer than five individuals at a time, primarily critics of Russia. The cluster impersonates US State Department officials and has evolved from ASP phishing (June 2025) to OAuth phishing (June 2026), where victims are tricked into sharing verification codes from legitimate login sessions. Infrastructure includes phishing domains dosportal.app and foreignrelations.us, with commercial residential proxies used for post-compromise activity.

UNC7005 (also tracked as STORM-2945 by Microsoft; moderate confidence: ICE RELIC/APT29 subcluster) demonstrates the broadest and most technically diverse toolkit. First identified in February 2026, the cluster targets academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the US. Key TTPs include: (1) ASP phishing with target-unique app passwords; (2) Microsoft device-code phishing using spoofed event registration pages (GLOBSEC forum, embassy invites) with browser fingerprinting and headless browser detection for evasion; (3) WhatsApp device linking phishing (May-June 2026) where victims are lured into linking attacker-controlled devices and subsequently prompted to join fake voice calls that trigger malicious JavaScript recording audio/video via getUserMedia; (4) commodity infostealer delivery via MaaS (VIDAR for Windows, ATOMIC/AtomicStealer for macOS) distributed through spoofed summit companion app downloads; (5) OAuth phishing via cloud projects (August 2026) using domains spoofing the Finnish Operations Center (FOC); and (6) the CaptiveCrunch campaign (July 2026) — DNS poisoning of hotel and conference center captive portal Wi-Fi networks to redirect travelers to attacker-controlled infrastructure for adversary-in-the-middle credential theft and malware delivery.

UNC5976 (distinct suspected Russian intelligence service, not linked to ICE RELIC) targets military, aerospace, defense industrial base, and NGOs/think tanks primarily in Ukraine and Armenia. The cluster has been active since March 2026, conducting OAuth phishing via fake file-sharing websites that redirect victims through legitimate Google OAuth to attacker-controlled Google Cloud projects that harvest authentication tokens. UNC5976 also deploys HEADRUSH, a malicious Excel plugin that ultimately delivers an HTA downloader, distributed via a domain impersonating a Ukrainian research institute. The cluster has created at least 12 domains since March 2026 and is migrating away from Google infrastructure to other providers following Google's disruption efforts.

Microsoft's investigation of the CaptiveCrunch campaign revealed a sophisticated supply chain dimension: the compromises spanned multiple venues using common equipment and management systems, suggesting access to shared services within the captive portal ecosystem rather than isolated venue compromises. The campaign deployed CornFlake RAT (a full-featured Go-based Windows implant with ECDH P-256 encrypted C2, keylogging, audio/video surveillance, credential theft via ChromeKatz, and remote shell) and ChocoShell/CHERRYPIE (a PowerShell infostealer with AMSI bypass, UAC bypass chain, and CDP-based browser credential extraction that bypasses Chrome App-Bound Encryption). The ChocoShell script shows artifacts suggesting LLM-augmented development.

The campaigns are assessed by GTIG with high confidence as having a Russian nexus, based on targeting patterns, phishing themes, and shared operational techniques. The abuse of legitimate authentication features (OAuth, device code, app passwords) makes detection particularly challenging, as the authentication flows themselves are legitimate — only the resulting tokens are redirected to attacker infrastructure. Remediation recommendations include the use of Google's Advanced Protection Program (which blocks app password creation), disabling device-code authentication flows where not required, enforcing always-on full-tunnel VPN on corporate devices, and maintaining strict phishing-resistant MFA.

MITRE ATT&CK techniques used in TL-2026-2091

Defense Evasion

T1027 Obfuscated Files or Information; T1497.001 System Checks

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1098.005 Account Manipulation: Device Registration; T1543.003 Create or Modify System Process: Windows Service

Credential Access

T1056.001 Input Capture: Keylogging; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1573 Encrypted Channel

Initial Access

T1078 Valid Accounts; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Collection

T1119 Automated Collection; T1123 Audio Capture; T1125 Video Capture

Lateral Movement

T1534 Internal Spearphishing; T1550.001 Use Alternate Authentication Material: Application Access Token

Privilege Escalation

T1548.002 Bypass User Account Control

lateral-movement

T1550.001 Use Alternate Authentication Material: Application Access Token

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976

  • Google — Google Workspace
    Vulnerable versions: All versions using app-specific passwords
    Fixed in: Use Advanced Protection Program
  • Microsoft — Microsoft 365 / Entra ID
    Vulnerable versions: All versions with device-code authentication enabled
    Fixed in: Disable device-code flow via Conditional Access
  • WhatsApp — WhatsApp
    Vulnerable versions: All versions (device linking feature abused)
    Fixed in: Enforce registration locks and 2FA
  • Windows — Windows 10/11
    Vulnerable versions: All versions
    Fixed in: Deploy EDR with behavioral detection
  • macOS — macOS
    Vulnerable versions: All versions
    Fixed in: Gatekeeper, notarization, and XProtect

Remediation for Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976

Immediate actions

  • Enable Google Advanced Protection Program (APP) for high-risk users — prevents app password creation
  • Disable or restrict device-code authentication flow in Microsoft Entra ID via Conditional Access
  • Block known phishing domains at perimeter: dosportal.app, foreignrelations.us, chamber-ua.org, wa-connect.eu, wa-connect.net, wa-invite.com, wa-device.com, wa-meeting.com, shopinvite.org, my-invite.org, globsec.net, statistic-ms.live, owa-ms365.com, m365-owa.com, ms365-device.com, ms365-live.com, finishoperations.com, finishoperations.org, foc-share.com, share-foc.com, internal-share.com, foc-share.org, verify-drive.com, mail.kiis.co.uk
  • Block known C2 IPs: 31.57.243.154, 38.146.28.75, 104.194.159.150, 107.189.18.7, 107.189.26.194, 213.145.86.112, 38.146.28.132
  • Audit and revoke any legacy app-specific passwords in Google Workspace and Microsoft 365

Workarounds

  • Restrict 2-Step Verification to 'Only Security Keys' or 'Google Prompt' to prevent app password creation
  • Block device-code authentication flow in Microsoft Entra ID where not required for legitimate use cases
  • Disable Web Proxy Auto-Discovery (WPAD) via Group Policy where not required
  • Enforce registration locks and 2FA on personal messaging apps for high-risk personnel

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2/WebAuthn security keys) across all high-risk roles
  • Implement always-on full-tunnel VPN for all corporate devices — eliminate split-tunneling exceptions
  • Enforce encrypted DNS in strict mode (DoH/DoT with plaintext fallback disabled) on managed devices
  • Deploy EDR with behavioral detection for Windows service creation, AMSI tampering, and UAC bypass chains
  • Implement Conditional Access policies with sign-in risk and device compliance requirements
  • Conduct regular audits of OAuth consent grants and third-party app access
  • Establish routine device audit checks for linked WhatsApp devices and other messaging platforms
  • Implement network segmentation for IoT/captive portal devices separate from corporate networks

Timeline of Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976

  • Google Threat Intelligence publishes 'What's in an ASP?' documenting UNC6293 campaigns using app-specific passwords named 'ms.state.gov' targeting academics and critics of Russia.
  • Citizen Lab publishes 'Same Sea, New Phish' report detailing UNC6293 ASP phishing campaign targeting Keir Giles, a prominent Russia expert. Attackers impersonate US State Department official and trick target into creating app-specific passwords, bypassing MFA.
  • UNC6293 evolves ASP phishing delivery: victims now enter app password into an authentication form on a legitimate-looking website rather than sharing via email. PDF lure documents retain same screenshots from June 2025 campaign.
  • Volexity documents UNC6293 activity involving spoofed European security events for phishing campaigns.
  • UNC7005 first identified by Google Threat Intelligence. Cluster begins app password phishing operations with target-unique app passwords referencing specific social engineering themes.
  • UNC5976 OAuth phishing activity tracking begins. Cluster purchases file-sharing-themed domains and creates cloud projects to harvest OAuth authentication tokens.
  • UNC7005 conducts device code phishing campaign spoofing GLOBSEC forum. Registration page includes epicurean wine selection theme — a recurring ICE RELIC phishing hallmark. Domain my-invite.org resolves to 104.194.159.150.
  • UNC5976 deploys HEADRUSH malicious Excel plugin (SHA256: 2c7f4165967d6f7737b3fef87959846920b57a5368b531ad1427c7214d4c41a2) via domain impersonating a Ukrainian research institute. Ultimately delivers HTA downloader.
  • Microsoft observes Storm-2945 (UNC7005) manipulating DNS/HTTP traffic through hospitality captive portal networks. CaptiveCrunch campaign begins.
  • UNC7005 conducts limited ENGINELIGHT Go malware phishing operation from bounce@chamber-ua.org with WhatsApp-spoofing domain wa-connect.eu. C2: statistic-ms.live.
  • UNC7005 retools GLOBSEC phishing page within days, adding browser fingerprinting and headless browser detection evasion scripts after 'embassy security policy' artifact error in original template.
  • UNC7005 WhatsApp device linking phishing campaign begins. Victims lured into linking attacker-controlled WhatsApp devices, then prompted to join fake voice calls triggering malicious JS recording audio/video via getUserMedia.
  • UNC7005 launches broader MaaS phishing wave targeting prominent US-based academics, diplomats, and researchers focused on Russia/former Soviet states. Delivers VIDAR (Windows) and ATOMIC/AMOS (macOS) infostealers via spoofed summit companion app.
  • UNC6293 evolves to OAuth phishing: victims asked to share full URL or verification code after legitimate login, granting attackers account access. Phishing domains: dosportal.app, foreignrelations.us.
  • UNC7005 registers three OWA-themed domains (owa-ms365.com, m365-owa.com, ms365-device.com) via chikolimdrid@gmail.com. Same email previously registered ms365-live.com at IP 104.194.159.150.
  • ReliaQuest publishes threat spotlight on DNS poisoning tactics expanding to hospitality Wi-Fi, documenting compromised captive portal gateways at hotels, conference centers, and airports. Multiple US cities, India, and Saudi Arabia affected.
  • Microsoft publishes detailed CaptiveCrunch report documenting Storm-2945/UNC7005's full attack chain: DNS poisoning at hospitality venues, CornFlake RAT deployment, ChocoShell infostealer, and FruitStone C2 panel. Supply chain compromise of captive portal ecosystem suspected.
  • UNC7005 launches OAuth phishing campaign targeting European defense industry. Domains spoof Finnish Operations Center (FOC): foc-share.com, share-foc.com, finishoperations.com. Legitimate Google OAuth redirects to attacker-controlled testing-mode cloud project.
  • Google Threat Intelligence Group publishes comprehensive blog detailing all three clusters (UNC6293, UNC7005, UNC5976), their TTPs, attribution assessments, and infrastructure indicators.

Sources cited for Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976

Threats related to Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976

Detection coverage for TL-2026-2091

As of 2026-08-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2091 across Splunk SPL, Microsoft KQL and Sigma, covering 43 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats