HomeSecurityGoogle OAuth: Russian hackers take over Google accounts

Google OAuth: Russian hackers take over Google accounts

Three suspected Russian cyberespionage groups are exploiting legitimate login processes to compromise Google accounts. Google OAuth is being used as a trap to steal credentials, while WhatsApp is being turned into a device login tool controlled by the attackers.

Google accounts and Google OAuth

The Google Threat Intelligence Group (GTIG) attributes a high level of confidence in a Russian nexus to UNC6293, UNC7005 and UNC5976, while individual connections to the ICE RELIC group, formerly known as APT29, are assessed with varying degrees of certainty. Academics, diplomats, government agencies, defense companies and think tanks in Europe and the US are targeted. Google accounts are a key target because they can open access to many more services.

See also: CoreBreak: AWS, Google and Vercel patched critical AI agent vulnerabilities

How Google OAuth attacks target Google accounts

UNC7005 created websites that mimicked the Finnish Operations Center, a support organization for defense and security companies in Finland. The emails led to a page with options to “Get Access” or “Sign in With Google.” The user was redirected to the legitimate Google login page, but after authenticating, they were taken to an unverified cloud project under the control of the attackers.

From there, malicious scripts could collect the authentication token and deliver it to the team, without having to re-enter the password. The same logic was applied by UNC5976 to fake file-sharing pages, with at least 12 new domains since March. GTIG disabled the infrastructure it detected, but the team moved to other providers. The critical point is that the user sees a genuine login page, while the deception has been transferred before and after it. Thus, control mechanisms must consider not only whether the login was completed, but also which application requested access and to what destination the user was redirected.

Google OAuth login token theft

Google Threat Intelligence Group analysis also documents earlier UNC6293 campaigns, in which victims were asked to create an app password with a name that referred to the State Department. A newer variant asked for a full URL or verification code after a legitimate login. App passwords should not be shared and, when created for a suspicious request, should be revoked immediately.

The WhatsApp device connection trap

In May and June 2026, UNC7005 set up pages that mimicked WhatsApp and promised a secure call, encrypted chat, or document download. After asking for a phone number, the group would create a legitimate connection request from its own device. The page would show the visitor the real QR or linking code and instruct them to approve the connection.

After successful login, the attackers could gain access to the account and attempt additional actions. In a fake voice call, JavaScript recorded audio and video and sent them to a command and control infrastructure. The encrypted chat option displayed fake credentials and a second login page, while the offered file download was not identified by GTIG.

See also: ShinyHunters: Salesforce data theft via OAuth

Check account connected devices

Practical measures for accounts and devices

The SecNews technical team recommends that you carefully check the website address before each connection and not consider a message trustworthy just because it comes from a known person. Invitations to conferences, calls or documents should be confirmed by an independent communication channel and not through the information contained in the message itself.

Google accounts should review and revoke unknown app passwords, while high-risk users can consider the Advanced Protection Program. WhatsApp requires regular checking of the “Connected Devices” list, enabling two-step verification, and confirming security codes with a different channel.

Google accounts remain an attractive target because a successful token theft can bypass the expectation that the login was made from a legitimate page. The Hacker News’s coverage shows that the groups are not relying on a single trick. They are combining Google OAuth, Microsoft OAuth, WhatsApp devices, and malware, taking advantage of the fact that a service’s legitimate appearance does not guarantee a safe destination.

See also: Phishing campaign impersonates leading companies and steals Google accounts

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS