Google says Russian groups added OAuth abuse to targeted phishing
GTIG tracked UNC6293, UNC7005, and UNC5976 using OAuth phishing against government, defense, and academic targets. Microsoft tracks UNC6293 as Storm-2945; the clusters used login-URL and code requests, device-code phishing, and a fake Continue with Google button.

On August 21 The Register reported Google Threat Intelligence Group findings on three clusters — UNC6293, UNC7005, and UNC5976 — adding OAuth abuse to targeted phishing. The campaigns hit government, defense, and academic organizations.
What we know
- GTIG attributed OAuth phishing against government, defense, and academic targets to UNC6293, UNC7005, and UNC5976.
- In June 2026, UNC6293 asked victims to share a login URL or a verification code; Microsoft tracks that cluster as Storm-2945.
- UNC7005 used device-code phishing against Microsoft and WhatsApp.
- UNC5976 presented a fake Continue with Google button, then captured the token on a Google Cloud project URL.
Takeaways
- The tracked clusters treat OAuth consent and device codes as the access path, not a stolen password alone.
- Microsoft’s name for UNC6293 is Storm-2945.
- One lure copies Google’s Continue with Google button and lands the token on a Cloud project URL.
Source: The Register / Google


