By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Russian Hackers Exploit Google OAuth, WhatsApp for Account Hijacking

Three distinct suspected Russian cyber espionage threat clusters, identified as UNC6293, UNC7005, and UNC5976, have been observed exploiting legitimate authentication flows to compromise accounts of individuals working in critical sectors. These targeted sectors include academia, aerospace and defense, government entities, and think tanks, with victims identified across Europe and within the United States. The threat actors are leveraging a sophisticated technique that abuses the OAuth 2.0 authorization framework, commonly used by Google, and the account linking features of messaging applications like WhatsApp. This method allows them to bypass traditional security measures by impersonating legitimate services and tricking users into granting unauthorized access to their accounts. The clusters engage in persistent and adaptive operations, suggesting a long-term strategic objective to gain intelligence or disrupt targeted organizations. The exploitation of OAuth flows is particularly concerning because it relies on the trust users place in established platforms like Google. When a user approves an OAuth request, they are essentially granting an application permission to access specific data or perform actions on their behalf, without sharing their actual password. However, the threat actors are manipulating these flows to redirect users to malicious applications or phishing pages that mimic legitimate Google login screens. Once a user enters their credentials on these fake pages, the attackers gain access to their Google account. Furthermore, the attackers are reportedly using the linking feature of WhatsApp, which allows users to connect their accounts to web or desktop clients, to further their compromise. This could involve sending malicious links or messages through compromised accounts or leveraging the linking process to gain deeper access to user data or contacts. The targeting of individuals in academia, aerospace, defense, and government indicates a focus on espionage and intelligence gathering, aiming to acquire sensitive information related to national security, technological advancements, or policy decisions. The involvement of multiple distinct threat clusters suggests a coordinated or at least parallel effort by Russian state-sponsored actors to achieve these objectives. The adaptive nature of their tactics implies a continuous effort to refine their methods and evade detection by cybersecurity defenses. This campaign highlights the ongoing sophistication of nation-state sponsored cyber threats and the critical need for robust security awareness training and multi-factor authentication to protect against such advanced persistent threats.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.