Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical GitLab Code Injection Flaw CVE-2023-5006 Actively Exploited
August 21, 2026
Critical WordPress Plugin Bug Exposes Sites to Remote Code Execution
August 21, 2026
Claude Opus 5 AI Bypasses Obfuscated Binaries, Not Defeats Them
August 21, 2026
Home/Threats/Sandworm Exploits OAuth, WhatsApp to Hijack High-Value Accounts
Threats

Sandworm Exploits OAuth, WhatsApp to Hijack High-Value Accounts

Key Takeaways Suspected Russian state-sponsored groups are leveraging legitimate authentication and device-linking features, rather than traditional exploits, to compromise high-value accounts....

Sarah simpson
Sarah simpson
August 21, 2026 4 Min Read
4 0

Key Takeaways

  • Suspected Russian state-sponsored groups are leveraging legitimate authentication and device-linking features, rather than traditional exploits, to compromise high-value accounts.
  • Targets include individuals in academia, aerospace, defense, government, and think tanks across the US and Europe.
  • Attackers use sophisticated social engineering, impersonating trusted entities and events to trick victims into approving seemingly legitimate actions.
  • Campaigns involve abusing OAuth flows for Google and Microsoft accounts, as well as exploiting WhatsApp’s device-linking feature to gain access to private messages and media.
  • Beyond account takeover, some campaigns also distribute information-stealing malware like VIDAR and ATOMIC to Windows and macOS users.

Sophisticated Account Takeovers Target High-Value Individuals

Cyber-espionage groups, strongly suspected of having ties to the Russian state, are employing increasingly sophisticated tactics to compromise high-value accounts. These adversaries are eschewing traditional password cracking or software vulnerability exploitation in favor of manipulating legitimate sign-in and device-linking processes. Their campaigns are designed to trick targets into approving actions that appear authentic, thereby circumventing conventional security measures.

Table Of Content

  • Key Takeaways
  • Sophisticated Account Takeovers Target High-Value Individuals
  • Russian Hackers Abuse OAuth and WhatsApp Device Linking
  • UNC7005 (STORM-2945) Campaigns
  • Malware Distribution and Broader Impact

The affected individuals span critical sectors, including academia, aerospace, defense, government, non-profit organizations, and various think tanks across both Europe and the United States. Attackers craft highly personalized phishing lures, often disguised as conference invitations, diplomatic communications, file-sharing requests, or urgent messages that pressure recipients into rapid authentication.

Threat intelligence analysts at Google Cloud have identified three distinct clusters engaged in this activity: UNC6293, UNC7005, and UNC5976. These groups utilize a blend of phishing, OAuth abuse, theft of application-specific passwords, device-code manipulation, and malware distribution. Google assesses with high confidence that these clusters operate with a Russian nexus, a conclusion drawn from their consistent targeting patterns, thematic content of their phishing attempts, and operational methodologies, as detailed in their recent report.

Google Cloud said in a report that these operations are particularly concerning because victims often interact with genuine authentication pages or legitimate account features. This imbues the malicious activity with a veneer of safety, making it difficult to distinguish from normal interactions and creating a blind spot for organizations primarily monitoring corporate accounts. Previous instances of Russian device-code phishing have already demonstrated how attackers can weaponize legitimate sign-in workflows to harvest access tokens.

Russian Hackers Abuse OAuth and WhatsApp Device Linking

UNC7005 (STORM-2945) Campaigns

The threat group UNC7005, also known as STORM-2945, has been observed conducting highly targeted phishing operations against individuals deemed of interest to the Russian government. Their deceptive lures frequently impersonate legitimate events, embassies, conferences, or trusted organizations, coaxing recipients to register, access documents, or join a supposedly secure conversation.

One notable campaign, active during May and June 2026, focused on WhatsApp users. Victims were directed to a fraudulent webpage and prompted to enter their phone number. This page then initiated a legitimate WhatsApp device-linking request for an attacker-controlled device, displaying the authentic QR code or linking code to the unsuspecting target. If the victim approved this request within their WhatsApp application, the attacker successfully established a linked session, gaining unauthorized access to the victim’s messages. This tactic mirrors the broader risk highlighted by “WhatsApp GhostPairing” account hijacks, where social engineering transforms a standard companion-device feature into a vector for illicit account access.

Following a successful device link, UNC7005’s malicious pages would then present further deceptive options, such as a fake voice call, an encrypted chat, or a file-transfer prompt. The fraudulent call page incorporated malicious browser code capable of recording audio and video. In the case of the chat option, the page displayed credentials for a secondary login. Google Cloud’s analysis could not definitively determine the nature of the file offered in the file-transfer scenario.

The same UNC7005 cluster has also exploited OAuth authorization flows against both Google and Microsoft accounts. For instance, in August 2026, they utilized domains designed to impersonate the Finnish Operations Center, targeting individuals within Europe’s defense sector. When victims clicked “Sign in With Google,” they were redirected to a legitimate Google login page. After successful authentication, they were then rerouted to an attacker-controlled, unverified cloud project, which was designed to harvest authentication tokens. This method is particularly insidious as victims input their credentials on a genuine provider page, yet still grant attackers access, a tactic previously documented in prior reports on Google services phishing abuse.

Malware Distribution and Broader Impact

Beyond authentication abuse, UNC7005 expanded its operations in late May 2026 by distributing malware. A fake website promoting a Ukraine-related summit was used to deliver browser information stealers to both Windows and macOS users. Windows users were infected with VIDAR, while macOS users received ATOMIC. Both malware families are designed to exfiltrate sensitive browser data, including saved credentials, cookies, addresses, and payment information.

The core challenge posed by these actors is their proficiency in leveraging legitimate features and infrastructure, making their malicious activities difficult to distinguish from routine account usage. Furthermore, many of the targeted accounts are personal, often falling outside the scope of an employer’s standard security monitoring. This highlights a critical blind spot for many organizations.

For cybersecurity defenders, the implication is clear: the presence of a familiar invitation, a valid QR code, or an authentic sign-in page no longer guarantees the safety of a request. Similar <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/5403efe0-ef1f-4cf9-b423-205737060d77/Russian-Hackers-Abuse-OAuth-and-WhatsApp-Device-Linking-to-Hijack-High-Value-Accounts.pdf?AWSAccessKeyId=ASIA2F3EMEYE7SWBUQKL&Signature=IM5DFGCqujNY%2FEH%2B1p41G9X6OQ0%3D&x-amz-security-token=IQoJb3JpZ2luX2VjENv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDQaKsHG1dr2YlYVE4PDFEnDAF6NIrrU3ke4Q%2FEsl27hAIhAKkb0PyFCA968%2BAG7badT6E1wbKz1Q%2FYaAGH5XlLGUUwKvwECKT%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgxdZvUHznBNwCWCuOEq0ASblqQ%2Blk8qKCkTk%2BPWFp%2B1NiFEE62uRn%2B5IEspE3LFasWLuiFdWeq76cJaKjL%2FEIycK9yH1UNvhiCixjauoo7Lv5C4jXZ9IdtcB1lQQXtwe33EYUo7HezXjrWZMGpxdrf9Ah%2Bp4LEbbp%2BP9S8vjPFkpsrkPXDug41TINzHgkxwOHwnj09bNiljQmXRf1M9EJaA5CHA1UQbszh%2BcLrk8fbPlTRu9PYCPguCcYazcq4yPjJMql0XroUUtVD1D9gSJXnqhs%2FJT8uRCoLoLMo0ZJyC7lhmG4Z4ItFZmn2Vk1uxW9GfYUFyIcrDKPBMY0B5rE2nvOYDLyA%2B%2BjaULDqVkzv%2Bjqc1BtzLd249BKy%2B0IOpwkDi0d5olOajl8iqmv7e8N5WSY7Klgwn%2FzF7TGHYyHkairLkz%2BFLQEgFW8eMGRnV2dRkHRYVL%2Bb7UJO0mFUZxf1qGk9cg%2BcFWIWNVKAdfSoJBTRZWr5dnNBCRMBs9qJW6R9fNuPKlO2qC%2FZNzBqTgi459JDNl%2BxbVwsOhMrLmfeIeS5xlrmU2e08yXguvxUXF%2FR4wwvhg%2BLoePuAn

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Fake Google Gemini installer deploys Vidar Stealer, steals browser data

Next Post

Critical N-able Passportal Flaw Exposes Password Vaults, 2FA Codes

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Sandworm Exploits OAuth, WhatsApp to Hijack High-Value Accounts
August 21, 2026
Fake Google Gemini installer deploys Vidar Stealer, steals browser data
August 21, 2026
Critical Vulnerability in Dameware Mini Remote Control Exposes Networks
August 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us