Suspected Russian clusters abuse Google OAuth and WhatsApp linking
Source headline: Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Intelligence Summary
Three distinct suspected Russian cyber espionage clusters are reported abusing legitimate authentication flows. The clusters target individuals in academia, aerospace and defense, governments, and think tanks across Europe, and also academia and think tanks within the U.S. The activity is linked to using Google OAuth and WhatsApp linking to hijack accounts. Campaign identifiers UNC6293, UNC7005, and UNC5976 are named as part of the observed activity. The report highlights persistent, adaptive behavior to single out specific victims. Users should review their Google OAuth and WhatsApp account linking and remove any suspicious linked sessions or apps.
Recommended Action
Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.