Google says Russian groups added OAuth abuse to targeted phishing
GTIG tracked UNC6293, UNC7005, and UNC5976 using OAuth phishing against government, defense, and academic targets. Microsoft tracks UNC6293 as Storm-2945; the clusters used login-URL and code requests, device-code phishing, and a fake Continue with Google button.



