Russian espionage groups weaponize OAuth and WhatsApp linking flows
Three suspected Russian clusters exploit legitimate Google and WhatsApp authentication to compromise targets in defense, government, and research sectors across Europe and the U.S.
Three distinct Russian-linked espionage clusters—UNC6293, UNC7005, and UNC5976—are abusing trusted authentication mechanisms to infiltrate high-value targets. The groups exploit Google OAuth flows and WhatsApp account linking processes, turning routine login procedures into vectors for account takeover.
Targets span academia, aerospace and defense contractors, government agencies, and think tanks in Europe and the United States. The campaigns reflect persistent, adaptive tradecraft: rather than deploying novel exploits, the operators manipulate authentication flows users encounter daily. By hijacking OAuth tokens or intercepting WhatsApp linking requests, attackers gain durable access without triggering conventional defenses.
The technique is effective because it leverages user trust in familiar platforms. Victims authenticate through legitimate Google or WhatsApp interfaces, unaware that the session is being captured or redirected. Once inside, adversaries can maintain persistence, exfiltrate communications, and pivot to adjacent accounts or systems.
- 01Defense contractors and government agencies face elevated risk of credential compromise via trusted platforms.
- 02Think tanks and academic institutions must audit OAuth grants and linked device sessions.
- 03Security teams should monitor for anomalous OAuth token issuance and WhatsApp linking events.
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.