Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts

Russian Cyber Espionage Infrastructure Uses Evilginx and (TL-2026-2167), also tracked as CaptiveCrunch, is a high-severity advanced persistent threat campaign, first published 2026-08-27. It is attributed to UNC6293 (Russia) with medium confidence, affects Google Google Workspace OAuth / Application-Specific Passwords, maps to 19 MITRE ATT&CK techniques (T1059.007, T1071.001, T1090.002), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-2167

Threat ID
TL-2026-2167
Also known as
CaptiveCrunch
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-08-27
Last reviewed
2026-08-27
Attribution
UNC6293
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, academia, aerospace, defense, think tanks, ngo, diplomatic, hospitality
Target regions
Europe, united states of america, ukraine, armenia
Detection rules
9
Indicators of compromise
30

Malware and tooling in Russian Cyber Espionage Infrastructure Uses Evilginx and

Malware and tooling: AMOS, Evilginx, HEADRUSH, Vidar, evilginx2 - S9003

Three Russian-nexus clusters — UNC6293 and UNC7005 (subclusters of ICE RELIC/APT29/Cozy Bear/Midnight Blizzard, UNC7005 also tracked as Storm-2945) and the independently-attributed UNC5976 — are compromising government, academic, aerospace, defense, and think-tank accounts across Europe, the US, Ukraine, and Armenia by abusing legitimate authentication features (app-specific passwords, OAuth consent, Microsoft/WhatsApp device-code flows) and Evilginx adversary-in-the-middle reverse-proxy infrastructure rather than exploiting software vulnerabilities. The campaign, active from at least June 2025 through August 2026, bypasses MFA, harvests session cookies/OAuth tokens, and delivers infostealer and RAT payloads (Vidar, Atomic/AMOS, HEADRUSH, CHERRYPIE/ChocoShell, ENGINELIGHT, CornFlake RAT) via credential-theft and malware-as-a-service infrastructure.

How Russian Cyber Espionage Infrastructure Uses Evilginx and works

Google Threat Intelligence Group (GTIG) publicly linked three distinct but related Russian-nexus clusters conducting large-scale account-compromise operations against individuals and institutions of interest to Russia. UNC6293, first detailed by Google and Citizen Lab in June 2025, is assessed with moderate confidence as an initial-access subcluster of ICE RELIC (the successor tracking name for APT29/Cozy Bear/Midnight Blizzard/Nobelium/BlueBravo). UNC6293 began by impersonating US State Department officials to solicit application-specific passwords (named e.g. 'ms.state.gov') via email and PDF walkthroughs, then evolved by October 2025 to harvesting ASPs entered on attacker phishing sites, and by June 2026 to abusing OAuth by asking targets to relay a post-login 'verification code' after a legitimate sign-in — effectively handing the attacker an OAuth authorization grant. This activity is hosted on Evilginx-style reverse-proxy infrastructure (subdomains of stateaffairs[.]us and related domains such as foreignrelations[.]us, dosportal[.]app, and internationalaffairsportal[.]us) that transparently relays victims to real US State Department pages while capturing credentials, session cookies, and MFA tokens in transit — the classic adversary-in-the-middle (AiTM) pattern documented for the open-source evilginx2 framework.

UNC7005 (aka Storm-2945), first identified in February 2026 and linked by Microsoft to Midnight Blizzard, targets academia, diplomatic personnel, and NGOs in Ukraine, Western Europe, and the US with lower operational security than UNC6293 but a heavier malware and infrastructure footprint. UNC7005 conducts Microsoft Entra ID and WhatsApp device-code phishing: victims are lured via spoofed conference/embassy-invite pages (reusing a template across an 'embassy invite' April 2026 lure and a GLOBSEC Forum 2026 spoof in May 2026) into approving a device-code login, or into linking WhatsApp to an attacker-controlled device under the pretense of joining a secure call — after which attacker-injected JavaScript can silently record audio/video during the resulting 'call' or harvest chat credentials. From May 2026, Microsoft/ReliaQuest/Zscaler documented a related sub-campaign, CaptiveCrunch, in which UNC7005/Storm-2945 manipulated shared hospitality-sector Wi-Fi captive portals worldwide to redirect travelers to Microsoft 365 credential-harvesting and device-code phishing pages, escalating from mid-July 2026 into direct AiTM abuse of the Entra ID device-code flow and delivering CornFlake RAT and ChocoShell (CHERRYPIE). In parallel, UNC7005 ran a malware-as-a-service infostealer campaign (May 2026) delivering Vidar (Windows, Go-based, C2 107.189.18.7) and Atomic/AMOS (macOS) via summit-themed phishing, and a smaller ENGINELIGHT Go-malware operation (April–May 2026, C2 statistic-ms.live) distributed from bounce@chamber-ua.org. By July–August 2026, UNC7005 registered domains spoofing the Finnish Operations Center and Microsoft OWA to target the European defense industry directly with OAuth/device-code phishing, including sending legitimate Microsoft OAuth URLs straight to victims and abusing unverified Google Cloud test-mode projects to capture OAuth tokens.

UNC5976, active since March 2026 and assessed as a separate Russian-nexus cluster (possibly a different intelligence service), focuses on military, aerospace, defense-industrial, NGO, and think-tank targets in Ukraine and Armenia. It automates OAuth token theft using fake file-sharing domains (verify-drive[.]com, drive.google.verify-drive[.]com) paired with attacker-owned Google Cloud projects: victims see an automatic 'Continue with Google' popup, complete a legitimate OAuth login, and are silently redirected through a malicious script that exfiltrates the resulting access token. UNC5976 also distributed HEADRUSH, a malicious Excel add-in leading to an HTA downloader, from a domain masquerading as a Ukrainian research institute, likely targeting a Ukrainian aerospace/imaging company. Following GTIG's disruption of its Google-hosted infrastructure, UNC5976 has migrated to non-Google cloud providers.

Across all three clusters, the unifying tradecraft is abuse of legitimate identity and authentication workflows — app-specific passwords, OAuth consent screens, and device-code/QR-based linking — rather than a software vulnerability, making the activity resistant to traditional patch-based remediation and dependent on identity-layer controls (phishing-resistant MFA, ASP restriction, OAuth-grant auditing, and device-link monitoring) for detection and response.

MITRE ATT&CK techniques used in TL-2026-2167

Execution

T1059.007 JavaScript; T1204.001 Malicious Link; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1090.002 External Proxy

Credential Access

T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Collection

T1123 Audio Capture; T1125 Video Capture

Defense Evasion

T1497.001 System Checks

lateral-movement

T1550.001 Application Access Token

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1583.006 Web Services; T1585.002 Email Accounts; T1588.001 Malware

Affected products and versions in Russian Cyber Espionage Infrastructure Uses Evilginx and

  • Google — Google Workspace OAuth / Application-Specific Passwords
    Vulnerable versions: legitimate feature abuse, not a software flaw
    Fixed in: N/A - identity/policy controls apply
  • Microsoft — Microsoft Entra ID device code authentication flow / Microsoft 365
    Vulnerable versions: legitimate feature abuse, not a software flaw
    Fixed in: N/A - identity/policy controls apply
  • Meta — WhatsApp device linking
    Vulnerable versions: legitimate feature abuse, not a software flaw
    Fixed in: N/A - identity/policy controls apply

Remediation for Russian Cyber Espionage Infrastructure Uses Evilginx and

Immediate actions

  • Disable application-specific passwords org-wide, or restrict account security to 'Security Keys only' for at-risk users
  • Block known malicious domains and IPs (stateaffairs.us cluster, UNC7005/UNC5976 infrastructure) at email gateways, DNS, and web proxies
  • Audit and revoke suspicious OAuth app grants and unverified/testing-mode cloud-project consents on Google Workspace and Microsoft 365 tenants
  • Audit and remove unrecognized linked devices on WhatsApp and similar linking-capable platforms

Workarounds

  • Require independent, off-platform verification of conference, embassy, and event invitations before registering or authenticating
  • Disable or closely monitor device-code authentication flows for Microsoft Entra ID tenants where not operationally required
  • Advise traveling staff to use VPN rather than authenticating directly through hotel/conference Wi-Fi captive portals

Longer-term hardening

  • Enforce phishing-resistant MFA (FIDO2/WebAuthn security keys) for diplomats, academics, defense-industry, and think-tank personnel
  • Enroll high-risk individuals in Google Advanced Protection Program / Microsoft equivalent
  • Deploy conditional access policies that block or flag OAuth device-code and app-password authentication paths by default
  • Monitor captive-portal and public Wi-Fi authentication traffic for DNS/HTTP manipulation consistent with CaptiveCrunch-style AiTM redirection

Timeline of Russian Cyber Espionage Infrastructure Uses Evilginx and

  • UNC6293 application-specific-password phishing campaign first publicly detailed by Google and Citizen Lab, impersonating US State Department officials with an 'ms.state.gov' app-password lure.
  • UNC6293 evolves ASP phishing to have targets enter their app password directly into an attacker-controlled phishing website rather than share it via email.
  • Volexity documents UNC6293 diplomatic/security-event-themed phishing lures targeting European security-conference attendees.
  • UNC7005 (Storm-2945) identified as a distinct cluster, beginning high-risk targeting of academia, diplomatic personnel, and NGOs in Ukraine, Western Europe, and the US.
  • UNC5976 begins automated OAuth token-collection operations using fake file-sharing domains paired with attacker-owned Google Cloud projects.
  • UNC5976 distributes the HEADRUSH malicious Excel add-in/HTA downloader from a domain spoofing a Ukrainian research institute; UNC7005 stands up my-invite.org device-code phishing infrastructure resolving to 104.194.159.150.
  • UNC7005 launches WhatsApp device-linking abuse operations (with JavaScript-based audio/video recording of resulting calls) and a summit-themed malware-as-a-service campaign delivering Vidar and Atomic/AMOS infostealers; GLOBSEC Forum 2026 registration page spoofed, reusing the 'embassy invite' device-code phishing template.
  • UNC6293 begins OAuth 'verification code' phishing via foreignrelations[.]us, impersonating US State Department officials to obtain OAuth authorization grants after a legitimate login.
  • UNC7005 registers Microsoft OWA-themed spoof domains (owa-ms365.com, m365-owa.com, ms365-device.com) escalating the hospitality-network AiTM campaign.
  • ReliaQuest reports DNS/HTTP traffic manipulation on shared hotel and conference-center Wi-Fi captive portals redirecting travelers into Microsoft Entra ID device-code AiTM phishing.
  • Microsoft publicly attributes the CaptiveCrunch captive-portal campaign to Storm-2945/Midnight Blizzard, detailing delivery of CornFlake RAT and ChocoShell (CHERRYPIE).
  • UNC7005 sends Finnish Operations Center-themed spearphishing emails to European defense-industry targets from foc-share[.]com and related domains, continuing through August 13, 2026.
  • Validin publishes an infrastructure analysis of the stateaffairs[.]us Evilginx reverse-proxy phishing cluster tied to the broader campaign.

Sources cited for Russian Cyber Espionage Infrastructure Uses Evilginx and

More in apt

Detection coverage for TL-2026-2167

As of 2026-08-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2167 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats