Cybercriminals do not always need convincing fake login pages anymore. Increasingly, attackers are finding that it can be more effective to place legitimate authentication services inside a fraudulent workflow, making attacks far more difficult for victims and security teams to recognise.
Recent cybersecurity findings have highlighted three Russian-linked cyber espionage activity clusters — UNC6293, UNC7005 and UNC5976 — conducting targeted phishing and social-engineering campaigns against people working in academia, aerospace and defence, government and other strategically sensitive sectors across Europe and the United States.
What makes these campaigns especially concerning is that the Google or WhatsApp page shown to a victim may actually be genuine. The deception takes place around those trusted authentication processes rather than replacing them completely.
Attackers Are Abusing Genuine Google OAuth Pages
One of the most significant techniques involves Google OAuth phishing.
UNC5976 reportedly created domains designed to resemble legitimate file-sharing services and connected them to cloud infrastructure controlled by the attackers.
Victims arriving at these websites were shown a familiar-looking interface containing a "Continue with Google" option.
The dangerous part is that clicking the button really does redirect the victim to a legitimate Google OAuth authentication page.
That immediately makes the attack more convincing.
People have long been taught to check whether they are signing in through an authentic Google page before entering credentials. In this situation, they may perform that check correctly and still become victims.
After authentication is completed, users can be redirected toward attacker-controlled cloud infrastructure, where authentication information or tokens may be captured or abused.
The attacker therefore does not necessarily need to steal the victim's Google password.
Instead, the objective may be to capture an OAuth token, verification code or another authentication artefact capable of providing access.
This changes an important assumption surrounding phishing: a genuine login page does not necessarily mean the entire process is trustworthy.
UNC7005 Targets Defence-Related Individuals
Another activity cluster, UNC7005, reportedly adopted a similar technique.
The attackers registered domains designed to resemble the legitimate Finnish Operations Center and targeted individuals connected with Europe's defence sector.
These campaigns appear to be carefully targeted rather than purely opportunistic.
Instead of sending millions of generic phishing emails, some attackers appear to focus on people whose accounts, communications or professional relationships may have intelligence value.
That includes diplomats, academics, researchers, defence personnel and government employees.
The smaller number of targets also allows attackers to spend more time preparing convincing messages around specific organisations, events and professional relationships.
Some Campaigns Target Fewer Than Five People
UNC6293, previously associated by Google with the Ice Relic activity cluster, has reportedly conducted highly selective phishing campaigns using impersonation and diplomatic-themed lures.
Some campaigns involved fewer than five victims.
The group had previously abused Google application-specific passwords but has since expanded into OAuth-based techniques.
Victims have also been asked to share URLs or verification codes after completing otherwise legitimate authentication steps.
This approach demonstrates that phishing is increasingly about manipulating the complete authentication workflow rather than simply presenting somebody with a fake password box.
WhatsApp Device Linking Can Also Be Exploited
Google is not the only trusted platform being incorporated into these attacks.
UNC7005 has also reportedly abused WhatsApp's legitimate device-linking functionality.
Victims were directed toward phishing pages claiming that their WhatsApp account needed to be connected to another device before they could participate in a secure call, conversation or document exchange.
The victim would provide their phone number.
The attackers would then initiate a genuine WhatsApp device-linking request from a device under their control.
The phishing page could subsequently display the legitimate QR code or linking code and instruct the victim to complete the process.
If the victim follows those instructions, the attacker's device may successfully become linked to the victim's WhatsApp account.
Again, no password theft is necessarily required.
WhatsApp's security mechanism is operating normally.
The victim has simply been manipulated into authorising the wrong device.
The Attack Can Continue After WhatsApp Is Compromised
Successfully linking a malicious device may only be one part of the attack.
Afterwards, the phishing interface can continue presenting additional prompts designed to collect information from the victim.
UNC7005 has also reportedly used information-stealing malware including Vidar and Atomic, also known as AMOS, against Windows and macOS systems.
Targets have included academics, diplomats and researchers focused on Russia and former Soviet states.
Some victims reportedly received emails containing links to pages impersonating events or organisations associated with support for Ukraine.
Those pages then encouraged users to download what appeared to be a companion application.
Instead, the download could install an information stealer.
This demonstrates how modern campaigns can combine multiple techniques depending on the victim.
One target may be tricked into linking WhatsApp.
Another may surrender an OAuth token.
Another may install malware.
The attacker can choose whichever path is most effective.
Compromised Wi-Fi Networks Create Another Risk
The wider activity has also been connected with a campaign known as CaptiveCrunch, which targets users through compromised captive Wi-Fi environments.
Hotels, airports and conference centres are among the environments reportedly associated with these attacks.
Instead of compromising every connected device directly, attackers may manipulate Wi-Fi infrastructure or DNS traffic so that selected users are redirected toward attacker-controlled authentication systems.
This could be particularly effective against people travelling for government, defence, academic or corporate work.
A user connecting to hotel Wi-Fi may believe they are simply going through an ordinary captive portal before accessing the internet.
In reality, the network itself may be directing them towards malicious infrastructure.
For high-value individuals who travel frequently, public and semi-public Wi-Fi networks therefore deserve considerably more caution.
Managed Service Providers Could Expand an Attack
Another worrying possibility involves managed service providers, or MSPs.
If attackers compromise an MSP responsible for managing Wi-Fi infrastructure or captive portals for multiple clients, that access could potentially be extended across several organisations and locations.
One compromised trusted provider may therefore expose infrastructure serving numerous customers.
This illustrates why third-party access is increasingly becoming a major cybersecurity concern.
An organisation may maintain strong security internally but still be exposed through a supplier that possesses privileged access to important infrastructure.
Cybersecurity therefore cannot stop at the organisation's own perimeter.
Trusted vendors and partners also need to be evaluated carefully.
CornFlake RAT and ChocoShell Add More Surveillance Capabilities
CaptiveCrunch activity has also been linked with malware including CornFlake RAT and ChocoShell.
CornFlake RAT reportedly supports a broad range of capabilities, including system reconnaissance, file collection, keystroke capture, credential theft, session-token theft, removable-media monitoring, audio and video capture and remote-shell access.
ChocoShell focuses more heavily on information theft.
It can target browser session cookies, saved passwords, Microsoft 365 authentication material and Wi-Fi credentials.
The infrastructure reportedly uses a centralised web-based command-and-control panel known as FruitStone for managing compromised devices and collected information.
At that stage, the attack has progressed far beyond ordinary phishing.
A compromised computer could effectively become a surveillance platform controlled remotely by the attacker.
Why These Attacks Are So Difficult to Detect
One of the biggest challenges is that substantial parts of the activity can look completely legitimate.
Traditional security controls often search for indicators such as:
Those indicators remain useful, but they do not cover every modern attack.
An attacker can direct the victim through an authentic Google login page or use WhatsApp's real device-linking system.
That allows malicious activity to blend into ordinary authentication traffic.
For users, this means checking the website address remains important, but it can no longer be the only security check.
The more important question may be:
If an unexpected email or message asks you to sign in with Google, provide a verification code, approve an OAuth request or connect another device to WhatsApp before viewing a document, that request deserves scrutiny even if the authentication screen itself appears genuine.
Security Teams Need to Monitor Authentication Behaviour
Organisations handling sensitive information should place greater emphasis on monitoring authentication workflows.
Recommended protections include watching for unusual OAuth consent and token activity, restricting unauthorised third-party OAuth applications, alerting on suspicious new-device registrations and detecting unexpected WhatsApp or collaboration-account linking.
Where practical, organisations should also deploy phishing-resistant multi-factor authentication.
User training remains equally important.
Employees should be encouraged to question unexpected authentication requests received through email, messaging platforms or unfamiliar websites.
Security teams should also monitor logins originating from unusual infrastructure or geographic locations, review privileged access provided to MSPs and other third parties, segment critical systems, watch for suspicious DNS or captive-portal behaviour, and investigate authentication activity that occurs shortly after targeted phishing attempts.
The Weakness Is Increasingly the Workflow
For years, phishing awareness often centred around one straightforward rule:
That advice is still correct.
But today's attackers have learned that they do not always need to create a fake Google page at all.
They can let Google authenticate the victim.
They can let WhatsApp generate the linking code.
They can let the legitimate security mechanism perform exactly the action it was designed to perform.
The social engineering takes place around that process.
The attacker simply convinces the victim to authorise something they never intended to authorise.
That means cybersecurity awareness needs to move beyond recognising fake websites and towards understanding context, permissions and authentication behaviour.
Final Thoughts
The campaigns involving UNC6293, UNC7005 and UNC5976 demonstrate how sophisticated social-engineering attacks are becoming.
Attackers are reportedly combining targeted phishing with genuine Google OAuth authentication, WhatsApp device linking, compromised Wi-Fi environments and information-stealing malware.
The most important lesson is simple:
A legitimate authentication page does not automatically make the overall transaction legitimate.
Users need to question why an authentication request appeared, what application is asking for permission and what access they are about to grant.
Organisations, meanwhile, need stronger monitoring around OAuth tokens, device registrations, third-party access and unusual authentication behaviour.
Modern phishing is increasingly moving beyond fake login screens.
Sometimes the attacker does not need to imitate the security system at all.
They simply convince the victim to use the real security system on the attacker's behalf.


Comments 0