Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US
Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 (TL-2026-2091), also tracked as CaptiveCrunch, is a high-severity advanced persistent threat campaign, first published 2026-08-21. It is attributed to APT29 (Russia) with high confidence, affects Google Google Workspace, maps to 25 MITRE ATT&CK techniques (T1027, T1053.005, T1056.001), and is covered by 9 detection rules and 43 indicators of compromise.
Key facts for TL-2026-2091
- Threat ID
- TL-2026-2091
- Also known as
- CaptiveCrunch, STORM-2945, Same Sea, New Phish
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-08-21
- Last reviewed
- 2026-08-21
- Attribution
- APT29
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- academia, aerospace, defense, government administration, think tanks, ngos, nonprofit, diplomatic, financial services, health, energy, legal
- Target regions
- ukraine, united states of america, 155 - Western Europe, 151 - Eastern Europe, armenia, india, saudi arabia
- Detection rules
- 9
- Indicators of compromise
- 43
Malware and tooling in Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976
Malware and tooling: AMOS, Vidar
Google Threat Intelligence Group tracks three distinct suspected Russian cyberespionage clusters — UNC6293, UNC7005, and UNC5976 — conducting targeted phishing campaigns against individuals in academia, aerospace, defense, government, and think tanks across Europe, Ukraine, and the US. UNC6293 and UNC7005 are linked to APT29 (Ice Relic / SVR) with moderate confidence, while UNC5976 is assessed as a distinct Russian intelligence service operation. The threat clusters abuse legitimate authentication flows — including OAuth token theft, application-specific password (ASP) phishing, device-code phishing, and WhatsApp device linking — and deliver commodity infostealers (VIDAR, ATOMIC/AMOS) and custom malware (CornFlake RAT, ChocoShell, ENGINELIGHT, HEADRUSH) via fake event registration pages, captive portal DNS poisoning at hotels and conference centers, and spoofed file-sharing portals.
How Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 works
Since at least mid-2025, three suspected Russian state-sponsored threat clusters have been conducting targeted phishing operations against individuals of interest to the Kremlin across academia, aerospace, defense, government, think tanks, and NGOs in Europe, Ukraine, and the United States. The operations are characterized by increasing sophistication in the abuse of legitimate authentication flows, including OAuth token theft, application-specific password (ASP) phishing, device-code phishing, and WhatsApp device linking.
UNC6293 (moderate confidence: ICE RELIC/APT29 subcluster) operates small-scale campaigns targeting fewer than five individuals at a time, primarily critics of Russia. The cluster impersonates US State Department officials and has evolved from ASP phishing (June 2025) to OAuth phishing (June 2026), where victims are tricked into sharing verification codes from legitimate login sessions. Infrastructure includes phishing domains dosportal.app and foreignrelations.us, with commercial residential proxies used for post-compromise activity.
UNC7005 (also tracked as STORM-2945 by Microsoft; moderate confidence: ICE RELIC/APT29 subcluster) demonstrates the broadest and most technically diverse toolkit. First identified in February 2026, the cluster targets academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the US. Key TTPs include: (1) ASP phishing with target-unique app passwords; (2) Microsoft device-code phishing using spoofed event registration pages (GLOBSEC forum, embassy invites) with browser fingerprinting and headless browser detection for evasion; (3) WhatsApp device linking phishing (May-June 2026) where victims are lured into linking attacker-controlled devices and subsequently prompted to join fake voice calls that trigger malicious JavaScript recording audio/video via getUserMedia; (4) commodity infostealer delivery via MaaS (VIDAR for Windows, ATOMIC/AtomicStealer for macOS) distributed through spoofed summit companion app downloads; (5) OAuth phishing via cloud projects (August 2026) using domains spoofing the Finnish Operations Center (FOC); and (6) the CaptiveCrunch campaign (July 2026) — DNS poisoning of hotel and conference center captive portal Wi-Fi networks to redirect travelers to attacker-controlled infrastructure for adversary-in-the-middle credential theft and malware delivery.
UNC5976 (distinct suspected Russian intelligence service, not linked to ICE RELIC) targets military, aerospace, defense industrial base, and NGOs/think tanks primarily in Ukraine and Armenia. The cluster has been active since March 2026, conducting OAuth phishing via fake file-sharing websites that redirect victims through legitimate Google OAuth to attacker-controlled Google Cloud projects that harvest authentication tokens. UNC5976 also deploys HEADRUSH, a malicious Excel plugin that ultimately delivers an HTA downloader, distributed via a domain impersonating a Ukrainian research institute. The cluster has created at least 12 domains since March 2026 and is migrating away from Google infrastructure to other providers following Google's disruption efforts.
Microsoft's investigation of the CaptiveCrunch campaign revealed a sophisticated supply chain dimension: the compromises spanned multiple venues using common equipment and management systems, suggesting access to shared services within the captive portal ecosystem rather than isolated venue compromises. The campaign deployed CornFlake RAT (a full-featured Go-based Windows implant with ECDH P-256 encrypted C2, keylogging, audio/video surveillance, credential theft via ChromeKatz, and remote shell) and ChocoShell/CHERRYPIE (a PowerShell infostealer with AMSI bypass, UAC bypass chain, and CDP-based browser credential extraction that bypasses Chrome App-Bound Encryption). The ChocoShell script shows artifacts suggesting LLM-augmented development.
The campaigns are assessed by GTIG with high confidence as having a Russian nexus, based on targeting patterns, phishing themes, and shared operational techniques. The abuse of legitimate authentication features (OAuth, device code, app passwords) makes detection particularly challenging, as the authentication flows themselves are legitimate — only the resulting tokens are redirected to attacker infrastructure. Remediation recommendations include the use of Google's Advanced Protection Program (which blocks app password creation), disabling device-code authentication flows where not required, enforcing always-on full-tunnel VPN on corporate devices, and maintaining strict phishing-resistant MFA.
MITRE ATT&CK techniques used in TL-2026-2091
Defense Evasion
T1027 Obfuscated Files or Information; T1497.001 System Checks
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1098.005 Account Manipulation: Device Registration; T1543.003 Create or Modify System Process: Windows Service
Credential Access
T1056.001 Input Capture: Keylogging; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1573 Encrypted Channel
Initial Access
T1078 Valid Accounts; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Collection
T1119 Automated Collection; T1123 Audio Capture; T1125 Video Capture
Lateral Movement
T1534 Internal Spearphishing; T1550.001 Use Alternate Authentication Material: Application Access Token
Privilege Escalation
T1548.002 Bypass User Account Control
lateral-movement
T1550.001 Use Alternate Authentication Material: Application Access Token
defense-impairment
Affected products and versions in Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976
- Google — Google Workspace
Vulnerable versions: All versions using app-specific passwords
Fixed in: Use Advanced Protection Program - Microsoft — Microsoft 365 / Entra ID
Vulnerable versions: All versions with device-code authentication enabled
Fixed in: Disable device-code flow via Conditional Access - WhatsApp — WhatsApp
Vulnerable versions: All versions (device linking feature abused)
Fixed in: Enforce registration locks and 2FA - Windows — Windows 10/11
Vulnerable versions: All versions
Fixed in: Deploy EDR with behavioral detection - macOS — macOS
Vulnerable versions: All versions
Fixed in: Gatekeeper, notarization, and XProtect
Remediation for Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976
Immediate actions
- Enable Google Advanced Protection Program (APP) for high-risk users — prevents app password creation
- Disable or restrict device-code authentication flow in Microsoft Entra ID via Conditional Access
- Block known phishing domains at perimeter: dosportal.app, foreignrelations.us, chamber-ua.org, wa-connect.eu, wa-connect.net, wa-invite.com, wa-device.com, wa-meeting.com, shopinvite.org, my-invite.org, globsec.net, statistic-ms.live, owa-ms365.com, m365-owa.com, ms365-device.com, ms365-live.com, finishoperations.com, finishoperations.org, foc-share.com, share-foc.com, internal-share.com, foc-share.org, verify-drive.com, mail.kiis.co.uk
- Block known C2 IPs: 31.57.243.154, 38.146.28.75, 104.194.159.150, 107.189.18.7, 107.189.26.194, 213.145.86.112, 38.146.28.132
- Audit and revoke any legacy app-specific passwords in Google Workspace and Microsoft 365
Workarounds
- Restrict 2-Step Verification to 'Only Security Keys' or 'Google Prompt' to prevent app password creation
- Block device-code authentication flow in Microsoft Entra ID where not required for legitimate use cases
- Disable Web Proxy Auto-Discovery (WPAD) via Group Policy where not required
- Enforce registration locks and 2FA on personal messaging apps for high-risk personnel
Longer-term hardening
- Deploy phishing-resistant MFA (FIDO2/WebAuthn security keys) across all high-risk roles
- Implement always-on full-tunnel VPN for all corporate devices — eliminate split-tunneling exceptions
- Enforce encrypted DNS in strict mode (DoH/DoT with plaintext fallback disabled) on managed devices
- Deploy EDR with behavioral detection for Windows service creation, AMSI tampering, and UAC bypass chains
- Implement Conditional Access policies with sign-in risk and device compliance requirements
- Conduct regular audits of OAuth consent grants and third-party app access
- Establish routine device audit checks for linked WhatsApp devices and other messaging platforms
- Implement network segmentation for IoT/captive portal devices separate from corporate networks
Timeline of Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976
- Google Threat Intelligence publishes 'What's in an ASP?' documenting UNC6293 campaigns using app-specific passwords named 'ms.state.gov' targeting academics and critics of Russia.
- Citizen Lab publishes 'Same Sea, New Phish' report detailing UNC6293 ASP phishing campaign targeting Keir Giles, a prominent Russia expert. Attackers impersonate US State Department official and trick target into creating app-specific passwords, bypassing MFA.
- UNC6293 evolves ASP phishing delivery: victims now enter app password into an authentication form on a legitimate-looking website rather than sharing via email. PDF lure documents retain same screenshots from June 2025 campaign.
- Volexity documents UNC6293 activity involving spoofed European security events for phishing campaigns.
- UNC7005 first identified by Google Threat Intelligence. Cluster begins app password phishing operations with target-unique app passwords referencing specific social engineering themes.
- UNC5976 OAuth phishing activity tracking begins. Cluster purchases file-sharing-themed domains and creates cloud projects to harvest OAuth authentication tokens.
- UNC7005 conducts device code phishing campaign spoofing GLOBSEC forum. Registration page includes epicurean wine selection theme — a recurring ICE RELIC phishing hallmark. Domain my-invite.org resolves to 104.194.159.150.
- UNC5976 deploys HEADRUSH malicious Excel plugin (SHA256: 2c7f4165967d6f7737b3fef87959846920b57a5368b531ad1427c7214d4c41a2) via domain impersonating a Ukrainian research institute. Ultimately delivers HTA downloader.
- Microsoft observes Storm-2945 (UNC7005) manipulating DNS/HTTP traffic through hospitality captive portal networks. CaptiveCrunch campaign begins.
- UNC7005 conducts limited ENGINELIGHT Go malware phishing operation from bounce@chamber-ua.org with WhatsApp-spoofing domain wa-connect.eu. C2: statistic-ms.live.
- UNC7005 retools GLOBSEC phishing page within days, adding browser fingerprinting and headless browser detection evasion scripts after 'embassy security policy' artifact error in original template.
- UNC7005 WhatsApp device linking phishing campaign begins. Victims lured into linking attacker-controlled WhatsApp devices, then prompted to join fake voice calls triggering malicious JS recording audio/video via getUserMedia.
- UNC7005 launches broader MaaS phishing wave targeting prominent US-based academics, diplomats, and researchers focused on Russia/former Soviet states. Delivers VIDAR (Windows) and ATOMIC/AMOS (macOS) infostealers via spoofed summit companion app.
- UNC6293 evolves to OAuth phishing: victims asked to share full URL or verification code after legitimate login, granting attackers account access. Phishing domains: dosportal.app, foreignrelations.us.
- UNC7005 registers three OWA-themed domains (owa-ms365.com, m365-owa.com, ms365-device.com) via chikolimdrid@gmail.com. Same email previously registered ms365-live.com at IP 104.194.159.150.
- ReliaQuest publishes threat spotlight on DNS poisoning tactics expanding to hospitality Wi-Fi, documenting compromised captive portal gateways at hotels, conference centers, and airports. Multiple US cities, India, and Saudi Arabia affected.
- Microsoft publishes detailed CaptiveCrunch report documenting Storm-2945/UNC7005's full attack chain: DNS poisoning at hospitality venues, CornFlake RAT deployment, ChocoShell infostealer, and FruitStone C2 panel. Supply chain compromise of captive portal ecosystem suspected.
- UNC7005 launches OAuth phishing campaign targeting European defense industry. Domains spoof Finnish Operations Center (FOC): foc-share.com, share-foc.com, finishoperations.com. Legitimate Google OAuth redirects to attacker-controlled testing-mode cloud project.
- Google Threat Intelligence Group publishes comprehensive blog detailing all three clusters (UNC6293, UNC7005, UNC5976), their TTPs, attribution assessments, and infrastructure indicators.
Sources cited for Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976
- Google Cloud Blog — Distinct clusters targeting individuals of interest to Russia
- Microsoft Security Blog — CaptiveCrunch: Midnight Blizzard targets travelers worldwide
- ReliaQuest — DNS Poisoning Tactics Expand to Hospitality Wi-Fi
- Citizen Lab — Same Sea, New Phish: Russian Government-Linked Social Engineering Targets App-Specific Passwords
- Google Threat Intelligence — What's in an ASP? Creative phishing targets academics and critics of Russia
- The Register — Russian snoops add OAuth abuse to targeted phishing campaigns
- The Hacker News — Suspected Russian Hackers Abuse Google, Microsoft OAuth in Targeted Phishing
- BleepingComputer — Russian hackers bypass Gmail MFA using stolen app passwords
- BleepingComputer — Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
- SecurityWeek — Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
- SANS ISC — Atomic macOS Stealer (AMOS) Infection
- Microsoft Security Blog — Hunting infostealers: macOS threats
Threats related to Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976
- CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deploy CornFlake RAT and ChocoShell Info-Stealer Against Corporate Travelers
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver CornFlake RAT and Steal Microsoft 365 Tokens
- CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive Portal Wi-Fi
- CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for credential theft and malware delivery
Detection coverage for TL-2026-2091
As of 2026-08-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2091 across Splunk SPL, Microsoft KQL and Sigma, covering 43 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.