Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
Russian Cyber Espionage Infrastructure Uses Evilginx and (TL-2026-2167), also tracked as CaptiveCrunch, is a high-severity advanced persistent threat campaign, first published 2026-08-27. It is attributed to UNC6293 (Russia) with medium confidence, affects Google Google Workspace OAuth / Application-Specific Passwords, maps to 19 MITRE ATT&CK techniques (T1059.007, T1071.001, T1090.002), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-2167
- Threat ID
- TL-2026-2167
- Also known as
- CaptiveCrunch
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-08-27
- Last reviewed
- 2026-08-27
- Attribution
- UNC6293
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, academia, aerospace, defense, think tanks, ngo, diplomatic, hospitality
- Target regions
- Europe, united states of america, ukraine, armenia
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in Russian Cyber Espionage Infrastructure Uses Evilginx and
Malware and tooling: AMOS, Evilginx, HEADRUSH, Vidar, evilginx2 - S9003
Three Russian-nexus clusters — UNC6293 and UNC7005 (subclusters of ICE RELIC/APT29/Cozy Bear/Midnight Blizzard, UNC7005 also tracked as Storm-2945) and the independently-attributed UNC5976 — are compromising government, academic, aerospace, defense, and think-tank accounts across Europe, the US, Ukraine, and Armenia by abusing legitimate authentication features (app-specific passwords, OAuth consent, Microsoft/WhatsApp device-code flows) and Evilginx adversary-in-the-middle reverse-proxy infrastructure rather than exploiting software vulnerabilities. The campaign, active from at least June 2025 through August 2026, bypasses MFA, harvests session cookies/OAuth tokens, and delivers infostealer and RAT payloads (Vidar, Atomic/AMOS, HEADRUSH, CHERRYPIE/ChocoShell, ENGINELIGHT, CornFlake RAT) via credential-theft and malware-as-a-service infrastructure.
How Russian Cyber Espionage Infrastructure Uses Evilginx and works
Google Threat Intelligence Group (GTIG) publicly linked three distinct but related Russian-nexus clusters conducting large-scale account-compromise operations against individuals and institutions of interest to Russia. UNC6293, first detailed by Google and Citizen Lab in June 2025, is assessed with moderate confidence as an initial-access subcluster of ICE RELIC (the successor tracking name for APT29/Cozy Bear/Midnight Blizzard/Nobelium/BlueBravo). UNC6293 began by impersonating US State Department officials to solicit application-specific passwords (named e.g. 'ms.state.gov') via email and PDF walkthroughs, then evolved by October 2025 to harvesting ASPs entered on attacker phishing sites, and by June 2026 to abusing OAuth by asking targets to relay a post-login 'verification code' after a legitimate sign-in — effectively handing the attacker an OAuth authorization grant. This activity is hosted on Evilginx-style reverse-proxy infrastructure (subdomains of stateaffairs[.]us and related domains such as foreignrelations[.]us, dosportal[.]app, and internationalaffairsportal[.]us) that transparently relays victims to real US State Department pages while capturing credentials, session cookies, and MFA tokens in transit — the classic adversary-in-the-middle (AiTM) pattern documented for the open-source evilginx2 framework.
UNC7005 (aka Storm-2945), first identified in February 2026 and linked by Microsoft to Midnight Blizzard, targets academia, diplomatic personnel, and NGOs in Ukraine, Western Europe, and the US with lower operational security than UNC6293 but a heavier malware and infrastructure footprint. UNC7005 conducts Microsoft Entra ID and WhatsApp device-code phishing: victims are lured via spoofed conference/embassy-invite pages (reusing a template across an 'embassy invite' April 2026 lure and a GLOBSEC Forum 2026 spoof in May 2026) into approving a device-code login, or into linking WhatsApp to an attacker-controlled device under the pretense of joining a secure call — after which attacker-injected JavaScript can silently record audio/video during the resulting 'call' or harvest chat credentials. From May 2026, Microsoft/ReliaQuest/Zscaler documented a related sub-campaign, CaptiveCrunch, in which UNC7005/Storm-2945 manipulated shared hospitality-sector Wi-Fi captive portals worldwide to redirect travelers to Microsoft 365 credential-harvesting and device-code phishing pages, escalating from mid-July 2026 into direct AiTM abuse of the Entra ID device-code flow and delivering CornFlake RAT and ChocoShell (CHERRYPIE). In parallel, UNC7005 ran a malware-as-a-service infostealer campaign (May 2026) delivering Vidar (Windows, Go-based, C2 107.189.18.7) and Atomic/AMOS (macOS) via summit-themed phishing, and a smaller ENGINELIGHT Go-malware operation (April–May 2026, C2 statistic-ms.live) distributed from bounce@chamber-ua.org. By July–August 2026, UNC7005 registered domains spoofing the Finnish Operations Center and Microsoft OWA to target the European defense industry directly with OAuth/device-code phishing, including sending legitimate Microsoft OAuth URLs straight to victims and abusing unverified Google Cloud test-mode projects to capture OAuth tokens.
UNC5976, active since March 2026 and assessed as a separate Russian-nexus cluster (possibly a different intelligence service), focuses on military, aerospace, defense-industrial, NGO, and think-tank targets in Ukraine and Armenia. It automates OAuth token theft using fake file-sharing domains (verify-drive[.]com, drive.google.verify-drive[.]com) paired with attacker-owned Google Cloud projects: victims see an automatic 'Continue with Google' popup, complete a legitimate OAuth login, and are silently redirected through a malicious script that exfiltrates the resulting access token. UNC5976 also distributed HEADRUSH, a malicious Excel add-in leading to an HTA downloader, from a domain masquerading as a Ukrainian research institute, likely targeting a Ukrainian aerospace/imaging company. Following GTIG's disruption of its Google-hosted infrastructure, UNC5976 has migrated to non-Google cloud providers.
Across all three clusters, the unifying tradecraft is abuse of legitimate identity and authentication workflows — app-specific passwords, OAuth consent screens, and device-code/QR-based linking — rather than a software vulnerability, making the activity resistant to traditional patch-based remediation and dependent on identity-layer controls (phishing-resistant MFA, ASP restriction, OAuth-grant auditing, and device-link monitoring) for detection and response.
MITRE ATT&CK techniques used in TL-2026-2167
Execution
T1059.007 JavaScript; T1204.001 Malicious Link; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1090.002 External Proxy
Credential Access
T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle
Collection
T1123 Audio Capture; T1125 Video Capture
Defense Evasion
lateral-movement
T1550.001 Application Access Token
Initial Access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1585.002 Email Accounts; T1588.001 Malware
Affected products and versions in Russian Cyber Espionage Infrastructure Uses Evilginx and
- Google — Google Workspace OAuth / Application-Specific Passwords
Vulnerable versions: legitimate feature abuse, not a software flaw
Fixed in: N/A - identity/policy controls apply - Microsoft — Microsoft Entra ID device code authentication flow / Microsoft 365
Vulnerable versions: legitimate feature abuse, not a software flaw
Fixed in: N/A - identity/policy controls apply - Meta — WhatsApp device linking
Vulnerable versions: legitimate feature abuse, not a software flaw
Fixed in: N/A - identity/policy controls apply
Remediation for Russian Cyber Espionage Infrastructure Uses Evilginx and
Immediate actions
- Disable application-specific passwords org-wide, or restrict account security to 'Security Keys only' for at-risk users
- Block known malicious domains and IPs (stateaffairs.us cluster, UNC7005/UNC5976 infrastructure) at email gateways, DNS, and web proxies
- Audit and revoke suspicious OAuth app grants and unverified/testing-mode cloud-project consents on Google Workspace and Microsoft 365 tenants
- Audit and remove unrecognized linked devices on WhatsApp and similar linking-capable platforms
Workarounds
- Require independent, off-platform verification of conference, embassy, and event invitations before registering or authenticating
- Disable or closely monitor device-code authentication flows for Microsoft Entra ID tenants where not operationally required
- Advise traveling staff to use VPN rather than authenticating directly through hotel/conference Wi-Fi captive portals
Longer-term hardening
- Enforce phishing-resistant MFA (FIDO2/WebAuthn security keys) for diplomats, academics, defense-industry, and think-tank personnel
- Enroll high-risk individuals in Google Advanced Protection Program / Microsoft equivalent
- Deploy conditional access policies that block or flag OAuth device-code and app-password authentication paths by default
- Monitor captive-portal and public Wi-Fi authentication traffic for DNS/HTTP manipulation consistent with CaptiveCrunch-style AiTM redirection
Timeline of Russian Cyber Espionage Infrastructure Uses Evilginx and
- UNC6293 application-specific-password phishing campaign first publicly detailed by Google and Citizen Lab, impersonating US State Department officials with an 'ms.state.gov' app-password lure.
- UNC6293 evolves ASP phishing to have targets enter their app password directly into an attacker-controlled phishing website rather than share it via email.
- Volexity documents UNC6293 diplomatic/security-event-themed phishing lures targeting European security-conference attendees.
- UNC7005 (Storm-2945) identified as a distinct cluster, beginning high-risk targeting of academia, diplomatic personnel, and NGOs in Ukraine, Western Europe, and the US.
- UNC5976 begins automated OAuth token-collection operations using fake file-sharing domains paired with attacker-owned Google Cloud projects.
- UNC5976 distributes the HEADRUSH malicious Excel add-in/HTA downloader from a domain spoofing a Ukrainian research institute; UNC7005 stands up my-invite.org device-code phishing infrastructure resolving to 104.194.159.150.
- UNC7005 launches WhatsApp device-linking abuse operations (with JavaScript-based audio/video recording of resulting calls) and a summit-themed malware-as-a-service campaign delivering Vidar and Atomic/AMOS infostealers; GLOBSEC Forum 2026 registration page spoofed, reusing the 'embassy invite' device-code phishing template.
- UNC6293 begins OAuth 'verification code' phishing via foreignrelations[.]us, impersonating US State Department officials to obtain OAuth authorization grants after a legitimate login.
- UNC7005 registers Microsoft OWA-themed spoof domains (owa-ms365.com, m365-owa.com, ms365-device.com) escalating the hospitality-network AiTM campaign.
- ReliaQuest reports DNS/HTTP traffic manipulation on shared hotel and conference-center Wi-Fi captive portals redirecting travelers into Microsoft Entra ID device-code AiTM phishing.
- Microsoft publicly attributes the CaptiveCrunch captive-portal campaign to Storm-2945/Midnight Blizzard, detailing delivery of CornFlake RAT and ChocoShell (CHERRYPIE).
- UNC7005 sends Finnish Operations Center-themed spearphishing emails to European defense-industry targets from foc-share[.]com and related domains, continuing through August 13, 2026.
- Validin publishes an infrastructure analysis of the stateaffairs[.]us Evilginx reverse-proxy phishing cluster tied to the broader campaign.
Sources cited for Russian Cyber Espionage Infrastructure Uses Evilginx and
- Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
- Distinct Clusters Target Individuals of Interest to Russia
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
- Midnight Blizzard launches CaptiveCrunch
- evilginx2, Software S9003
- Russia-Linked Hackers Exploit Legitimate Login Flows to Bypass 2FA and Steal Account Access
- Fake Conferences, OAuth and WhatsApp: Inside Russia's New Espionage Tactics
More in apt
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)
Detection coverage for TL-2026-2167
As of 2026-08-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2167 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.