Going with the Flow(s): Distin... Note

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Google Threat Intelligence Group is tracking five suspected Russian cyber espionage clusters targeting academia, aerospace, defense, government, and think tanks. These groups, including UNC6293, UNC7005, and UNC5976, employ various methods like phishing and abuse of legitimate authentication flows. The primary goal is to compromise user accounts by exploiting trust through sophisticated social engineering. UNC6293, potentially a sub-cluster of ICE RELIC, focuses on app password phishing, impersonating the U.S. State Department. This cluster targets individuals critical of Russia, luring them to set specific app passwords or share verification codes. UNC7005, also assessed as connected to ICE RELIC, exhibits lower sophistication and poorer operational security. It conducts app password phishing and device code phishing for Microsoft and WhatsApp accounts. UNC7005 uses elaborate social engineering, often spoofing legitimate events and organizations. Their tactics include system fingerprinting to evade detection and attempts to disguise operations. In WhatsApp phishing, UNC7005 aims to link user accounts to attacker-controlled devices. This allows for further compromise, including audio and video recording. While campaigns differ, the common thread is the abuse of authentication processes. GTIG is raising awareness to help targets identify these malicious social engineering efforts.
CdXz5zHNQW_JPYYRiseWZ.png