Sandworm Exploits OAuth, WhatsApp to Hijack High-Value Accounts
Key Takeaways Suspected Russian state-sponsored groups are leveraging legitimate authentication and device-linking features, rather than traditional exploits, to compromise high-value accounts....
Key Takeaways
- Suspected Russian state-sponsored groups are leveraging legitimate authentication and device-linking features, rather than traditional exploits, to compromise high-value accounts.
- Targets include individuals in academia, aerospace, defense, government, and think tanks across the US and Europe.
- Attackers use sophisticated social engineering, impersonating trusted entities and events to trick victims into approving seemingly legitimate actions.
- Campaigns involve abusing OAuth flows for Google and Microsoft accounts, as well as exploiting WhatsApp’s device-linking feature to gain access to private messages and media.
- Beyond account takeover, some campaigns also distribute information-stealing malware like VIDAR and ATOMIC to Windows and macOS users.
Sophisticated Account Takeovers Target High-Value Individuals
Cyber-espionage groups, strongly suspected of having ties to the Russian state, are employing increasingly sophisticated tactics to compromise high-value accounts. These adversaries are eschewing traditional password cracking or software vulnerability exploitation in favor of manipulating legitimate sign-in and device-linking processes. Their campaigns are designed to trick targets into approving actions that appear authentic, thereby circumventing conventional security measures.
Table Of Content
The affected individuals span critical sectors, including academia, aerospace, defense, government, non-profit organizations, and various think tanks across both Europe and the United States. Attackers craft highly personalized phishing lures, often disguised as conference invitations, diplomatic communications, file-sharing requests, or urgent messages that pressure recipients into rapid authentication.
Threat intelligence analysts at Google Cloud have identified three distinct clusters engaged in this activity: UNC6293, UNC7005, and UNC5976. These groups utilize a blend of phishing, OAuth abuse, theft of application-specific passwords, device-code manipulation, and malware distribution. Google assesses with high confidence that these clusters operate with a Russian nexus, a conclusion drawn from their consistent targeting patterns, thematic content of their phishing attempts, and operational methodologies, as detailed in their recent report.
Google Cloud said in a report that these operations are particularly concerning because victims often interact with genuine authentication pages or legitimate account features. This imbues the malicious activity with a veneer of safety, making it difficult to distinguish from normal interactions and creating a blind spot for organizations primarily monitoring corporate accounts. Previous instances of Russian device-code phishing have already demonstrated how attackers can weaponize legitimate sign-in workflows to harvest access tokens.
Russian Hackers Abuse OAuth and WhatsApp Device Linking
UNC7005 (STORM-2945) Campaigns
The threat group UNC7005, also known as STORM-2945, has been observed conducting highly targeted phishing operations against individuals deemed of interest to the Russian government. Their deceptive lures frequently impersonate legitimate events, embassies, conferences, or trusted organizations, coaxing recipients to register, access documents, or join a supposedly secure conversation.
One notable campaign, active during May and June 2026, focused on WhatsApp users. Victims were directed to a fraudulent webpage and prompted to enter their phone number. This page then initiated a legitimate WhatsApp device-linking request for an attacker-controlled device, displaying the authentic QR code or linking code to the unsuspecting target. If the victim approved this request within their WhatsApp application, the attacker successfully established a linked session, gaining unauthorized access to the victim’s messages. This tactic mirrors the broader risk highlighted by “WhatsApp GhostPairing” account hijacks, where social engineering transforms a standard companion-device feature into a vector for illicit account access.
Following a successful device link, UNC7005’s malicious pages would then present further deceptive options, such as a fake voice call, an encrypted chat, or a file-transfer prompt. The fraudulent call page incorporated malicious browser code capable of recording audio and video. In the case of the chat option, the page displayed credentials for a secondary login. Google Cloud’s analysis could not definitively determine the nature of the file offered in the file-transfer scenario.
The same UNC7005 cluster has also exploited OAuth authorization flows against both Google and Microsoft accounts. For instance, in August 2026, they utilized domains designed to impersonate the Finnish Operations Center, targeting individuals within Europe’s defense sector. When victims clicked “Sign in With Google,” they were redirected to a legitimate Google login page. After successful authentication, they were then rerouted to an attacker-controlled, unverified cloud project, which was designed to harvest authentication tokens. This method is particularly insidious as victims input their credentials on a genuine provider page, yet still grant attackers access, a tactic previously documented in prior reports on Google services phishing abuse.
Malware Distribution and Broader Impact
Beyond authentication abuse, UNC7005 expanded its operations in late May 2026 by distributing malware. A fake website promoting a Ukraine-related summit was used to deliver browser information stealers to both Windows and macOS users. Windows users were infected with VIDAR, while macOS users received ATOMIC. Both malware families are designed to exfiltrate sensitive browser data, including saved credentials, cookies, addresses, and payment information.
The core challenge posed by these actors is their proficiency in leveraging legitimate features and infrastructure, making their malicious activities difficult to distinguish from routine account usage. Furthermore, many of the targeted accounts are personal, often falling outside the scope of an employer’s standard security monitoring. This highlights a critical blind spot for many organizations.
For cybersecurity defenders, the implication is clear: the presence of a familiar invitation, a valid QR code, or an authentic sign-in page no longer guarantees the safety of a request. Similar <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/5403efe0-ef1f-4cf9-b423-205737060d77/Russian-Hackers-Abuse-OAuth-and-WhatsApp-Device-Linking-to-Hijack-High-Value-Accounts.pdf?AWSAccessKeyId=ASIA2F3EMEYE7SWBUQKL&Signature=IM5DFGCqujNY%2FEH%2B1p41G9X6OQ0%3D&x-amz-security-token=IQoJb3JpZ2luX2VjENv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDQaKsHG1dr2YlYVE4PDFEnDAF6NIrrU3ke4Q%2FEsl27hAIhAKkb0PyFCA968%2BAG7badT6E1wbKz1Q%2FYaAGH5XlLGUUwKvwECKT%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgxdZvUHznBNwCWCuOEq0ASblqQ%2Blk8qKCkTk%2BPWFp%2B1NiFEE62uRn%2B5IEspE3LFasWLuiFdWeq76cJaKjL%2FEIycK9yH1UNvhiCixjauoo7Lv5C4jXZ9IdtcB1lQQXtwe33EYUo7HezXjrWZMGpxdrf9Ah%2Bp4LEbbp%2BP9S8vjPFkpsrkPXDug41TINzHgkxwOHwnj09bNiljQmXRf1M9EJaA5CHA1UQbszh%2BcLrk8fbPlTRu9PYCPguCcYazcq4yPjJMql0XroUUtVD1D9gSJXnqhs%2FJT8uRCoLoLMo0ZJyC7lhmG4Z4ItFZmn2Vk1uxW9GfYUFyIcrDKPBMY0B5rE2nvOYDLyA%2B%2BjaULDqVkzv%2Bjqc1BtzLd249BKy%2B0IOpwkDi0d5olOajl8iqmv7e8N5WSY7Klgwn%2FzF7TGHYyHkairLkz%2BFLQEgFW8eMGRnV2dRkHRYVL%2Bb7UJO0mFUZxf1qGk9cg%2BcFWIWNVKAdfSoJBTRZWr5dnNBCRMBs9qJW6R9fNuPKlO2qC%2FZNzBqTgi459JDNl%2BxbVwsOhMrLmfeIeS5xlrmU2e08yXguvxUXF%2FR4wwvhg%2BLoePuAn
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.