Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical cPanel Vulnerability (CVE-2023-XXXX) Allows Full Server Control
August 28, 2026
Critical PaperCut NG/MF Vulnerability Actively Exploited in Attacks
August 28, 2026
GitLab Patches Critical AI Agent Flaw Allowing Code Execution
August 27, 2026
Home/Threats/Russian Hackers Exploit Fake Google Drive in Diplomatic Phishing Attacks
Threats

Russian Hackers Exploit Fake Google Drive in Diplomatic Phishing Attacks

Key Takeaways Russian state-sponsored actors are employing sophisticated phishing techniques, including fake Google Drive pages and diplomatic lures, to compromise high-value targets. The campaigns...

Jennifer sherman
Jennifer sherman
August 27, 2026 5 Min Read
9 0

Key Takeaways

  • Russian state-sponsored actors are employing sophisticated phishing techniques, including fake Google Drive pages and diplomatic lures, to compromise high-value targets.
  • The campaigns aim to steal online account credentials and access tokens, bypassing traditional malware deployment by leveraging legitimate authentication processes.
  • Targets primarily include individuals within academic institutions, think tanks, government-affiliated organizations, and defense sectors across Europe and the United States.
  • Initial access often involves convincing emails or web pages mimicking trusted services or events, prompting users to view documents or register for meetings.
  • The stolen credentials or tokens grant attackers access to sensitive data such as emails, cloud files, contacts, and confidential communications.

Russian-backed cyber espionage groups are actively deploying highly deceptive phishing operations, utilizing meticulously crafted fake cloud storage interfaces and politically themed invitations to gain unauthorized access to online accounts. These campaigns specifically target individuals within critical sectors, aiming to compromise sensitive information without relying on traditional malicious software downloads.

Table Of Content

  • Key Takeaways
  • Russian Hackers Use Fake Google Drive
  • Diplomatic Lures Broaden the Campaign
  • What You Should Do

Instead of distributing malware, these threat actors manipulate legitimate sign-in procedures, tricking victims into unknowingly granting access to their accounts. This sophisticated approach has been observed targeting personnel in academia, think tanks, governmental bodies, and defense-related organizations throughout Europe and the United States. The lures are designed to appear routine, often presenting as requests to view documents or register for events, using emails and web pages that mimic familiar services or institutions.

Analysts at Validin have uncovered additional infrastructure associated with these campaigns. Their investigation, detailed in a report shared with Cyber Security News (CSN), involved a comprehensive review of historical DNS records, website responses, digital certificates, registration data, and visual characteristics of the phishing pages. Validin said in a report that their findings build upon earlier research by Google Threat Intelligence Group, which had previously tracked these activities under the designations UNC6293, UNC7005, and UNC5976. The implications of these attacks are severe, even in the absence of traditional malware, as attackers can acquire critical access tokens.

The compromise of a consent token, device code, application password, or an active browser session can immediately grant an intruder access to a victim’s email, cloud storage, contact lists, and ongoing conversations. This level of access can expose routine work communications and potentially compromise sensitive diplomatic correspondence and interactions with external partners.

Russian Hackers Use Fake Google Drive

The UNC5976 cluster has been observed employing a domain designed to closely resemble Google Drive in its OAuth phishing operations. Validin successfully captured one such page, which bore the title “My Drive – Google Drive,” a subtle detail intended to reassure recipients expecting to interact with a legitimate file-sharing service.

OAuth phishing represents an advanced form of attack that exploits genuine authorization processes, rather than merely requesting credentials via a crude fake form. In this method, targets are redirected to an authentic service provider’s sign-in page, where they are then prompted to authorize an application controlled by the attacker. This authorization can grant the attackers tokens, enabling them to access account data without requiring the user’s password for future intrusions. Validin’s researchers identified consistent hosting and content patterns across multiple lookalike domains, underscoring the attackers’ ability to rapidly cycle their web infrastructure. This strategy aligns with previous reports detailing how Russian hackers exploit OAuth by using tailored themes to facilitate account takeovers.

Validin’s analysis also revealed a distinct fake Drive favicon and other matching page characteristics that allowed them to differentiate these malicious sites from a broader pool of potential targets. Such technical indicators are crucial because domain names can be quickly registered and abandoned by attackers. However, consistent page templates and server behaviors can expose the underlying, larger campaign.

Diplomatic Lures Broaden the Campaign

The UNC6293 cluster leveraged foreign policy-themed web lures to support its OAuth phishing initiatives. These lures incorporated content mirroring that of the Council on Foreign Relations, with associated domain names referencing international affairs and state matters. This gave the operation a highly credible appearance, specifically targeting individuals involved in policy and diplomacy.

Evidence also suggests the campaign employed proxy-based phishing tactics. Several subdomains linked to the operation briefly redirected visitors to legitimate websites, including those of the U.S. State Department and the Washington Ballet. Validin’s assessment indicates these responses are consistent with Evilginx configurations, a technique known for enabling the live interception of sign-in sessions.

A separate cluster, UNC7005, utilized fabricated event invitations to target Microsoft and WhatsApp accounts through device-code phishing. One particular lure advertised a supposed event in Prague, subtly altering its branding and deadlines over time to maintain credibility. This tactic highlights the increasing prevalence of using familiar account-linking screens, similar to those seen in Russian hacker operations spoofing European events, to make urgent authentication requests appear legitimate.

The combination of historical DNS data, captured web pages, certificate information, and domain registration records is vital for uncovering related malicious infrastructure. However, researchers caution that such pivots require careful verification, as shared hosting, expired DNS records, and copied web content can sometimes lead to misleading overlaps. Detailed technical indicators, including newly identified infrastructure, are provided below for defensive monitoring and blocking purposes.

Organisations should treat any unexpected Google Drive shares, conference invitations, or device-linking requests as potential attempts to compromise accounts, especially if they originate from unfamiliar domains. Users are advised to independently access the legitimate service rather than clicking on links within suspicious messages, carefully review the permissions requested by any OAuth application, and report all suspicious pages.

What You Should Do

  • Exercise Extreme Caution: Always be suspicious of unexpected emails or messages, particularly those involving file shares, conference invitations, or requests to link devices, especially if the sender or domain is unfamiliar.
  • Verify Independently: If prompted to open a document or register for an event, navigate directly to the official service (e.g., Google Drive, Microsoft 365, WhatsApp) through your browser, rather than clicking on links in the message.
  • Scrutinize OAuth Permissions: Before approving any third-party application via OAuth, carefully review the permissions it requests. Only grant access to applications you explicitly trust and understand.
  • Report Suspicious Activity: Immediately report any suspicious emails, web pages, or authentication requests to your organization’s IT security team.
  • Implement Phishing-Resistant Authentication: Organizations should deploy and enforce phishing-resistant multi-factor authentication (MFA) methods, such as FIDO2/WebAuthn security keys. These methods significantly reduce susceptibility to advanced phishing techniques like proxy-style attacks (e.g., Evilginx).
  • Monitor for Unusual Activity: Security teams should actively monitor for unusual consent grants to third-party applications and anomalous session activity within user accounts.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

OpenAI Agents Chain Zero-Days to Breach Hugging Face and Internal Systems

Next Post

Nutex Health Data Breach Exposes Patient Information

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TP-Link Kasa Smart Home Vulnerability Lets Attackers Disrupt Devices
August 27, 2026
CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks
August 27, 2026
Two Australians Charged for TeamPCP Supply Chain Attacks
August 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us