Russian-linked operators are using fake cloud-storage pages and diplomatic themes to trick targets into giving away access to online accounts. The following article body is 650 words, excluding the IoC table.
Russian cyber espionage campaigns are using convincing Google Drive pages and diplomatic invitations to take over online accounts.
Instead of relying on a malicious download, the operators steer targets into legitimate sign-in processes and capture the access they need.
The activity has focused on people in academia, think tanks, government-linked bodies, and defense-related organizations in Europe and the United States.
Emails and webpages imitate familiar services, events, or institutions, making a request to view a document or register for a meeting appear routine.
Analysts at Validin identified further infrastructure around the campaigns after examining historical DNS records, website responses, certificates, registration data, and visual page features.
Validin said in a report shared with Cyber Security News (CSN) that their work expands on reporting by Google Threat Intelligence Group, which tracked the activity under the clusters UNC6293, UNC7005, and UNC5976. The impact can be serious even when a victim never installs traditional malware.
A stolen consent token, device code, app password, or active browser session can give an intruder access to email, cloud files, contacts, and trusted conversations, during routine work and potentially exposing sensitive diplomatic correspondence and external partners.
The UNC5976 cluster used a Google Drive lookalike domain in an OAuth phishing operation. Validin captured the page with the title “My Drive – Google Drive,” a small detail designed to reassure a recipient who expected to open or share a file.
OAuth phishing abuses a real authorization process rather than simply asking for a password on a crude fake form. A target can be sent to a genuine provider sign-in page, then prompted to approve an attacker-controlled application.
That approval may hand over tokens that let attackers reach account data without needing the password again. The researchers found similar hosting and content patterns across additional lookalike domains, showing how quickly an operation can rotate its web infrastructure.
This approach aligns with earlier reporting on Russian hackers abuse OAuth, where tailored themes were used to push targets toward account takeovers.
Validin also recorded a distinctive fake Drive favicon and matching page characteristics that helped narrow a much larger set of possible sites.
Such technical traces matter because names alone are unreliable: attackers can register and abandon domains rapidly, while copied page templates and server behavior can expose a broader campaign.
UNC6293 used foreign policy-themed web lures to support OAuth phishing. The material copied content connected to the Council on Foreign Relations, while related names referenced international affairs and state matters, giving the operation a credible policy-focused appearance.
The campaign also showed signs of proxy-based phishing. Several campaign-linked subdomains briefly redirected visitors to legitimate U.S. State Department and Washington Ballet pages.
Validin assessed the responses as possible Evilginx configurations, a technique associated with live interception of sign-in sessions.
A separate cluster, UNC7005, used fake invitations to target Microsoft and WhatsApp accounts through device-code phishing. One lure promoted a supposed Prague event and changed its branding and deadline over time.
The tactic reflects the growing use of familiar account-linking screens, also seen in Russian hackers spoof European events, to make urgent authentication requests feel legitimate.
Combining historical DNS, page captures, certificate data, and registration records can uncover related infrastructure.
The researchers caution that pivots need verification, since shared hosting, expired DNS, and copied web content can create misleading overlaps.
Organizations should treat unexpected Drive shares, conference invitations, and device-linking requests as potential account-theft attempts, particularly when they arrive from an unfamiliar domain.
Users should independently open the service instead of following the message link, review an OAuth application’s requested permissions, and report suspicious pages.
Security teams should monitor unusual consent grants and session activity, while phishing-resistant sign-in methods can reduce exposure to proxy-style attacks described in Evilginx AiTM phishing attacks.
The technical indicators associated with this activity, including newly identified related infrastructure, appear in the table below for defensive monitoring and blocking.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | foreignrelations[.]us | UNC6293 OAuth phishing lure |
| Domain | dosportal[.]app | UNC6293 OAuth phishing lure |
| Domain | internationalaffairsportal[.]us | Suspected UNC6293-related domain |
| Domain | stateaffairs[.]us | Suspected UNC6293-related domain; possible proxy-phishing activity |
| Domain | the-washington-ballet[.]com | Suspected UNC6293-related domain; possible proxy-phishing activity |
| IP address | 151.236.15[.]213 | Possible origin IP for UNC6293-related infrastructure |
| IP address | 185.158.250[.]155 | Possible origin IP for UNC6293-related infrastructure |
| Email address | given956[@]2200freefonts[.]com | Registrant email associated with suspected UNC6293 domains |
| Domain | 2200freefonts[.]com | Domain used in the registrant email; not attributed to UNC6293 |
| Domain | my-invite[.]org | UNC7005 phishing infrastructure |
| IP address | 104.194.159[.]150 | Historical resolution for my-invite[.]org |
| Domain | ms365-live[.]com | Related infrastructure overlap |
| Domain | statistic-ms[.]live | UNC7005 redirect infrastructure |
| URL | https[:]//ad-g[.]org/login | Login page reached through statistic-ms[.]live |
| Domain | ad-g[.]org | UNC7005-related phishing infrastructure |
| Domain | drive[.]google[.]verify-drive[.]com | UNC5976 OAuth phishing lure |
| Domain | verify-drive[.]com | Related UNC5976 infrastructure |
| IP address | 93.127.160[.]28 | Historical hosting IP for verify-drive[.]com |
| Domain | fllefolder[.]com | Suspected UNC5976-related domain |
| Domain | sharefolders[.]org | Suspected UNC5976-related domain |
| Domain | drive[.]google[.]sharefolders[.]org | Suspected UNC5976-related domain |
| Domain | formshare[.]cloud | Suspected UNC5976-related domain |
| Domain | drive[.]google[.]formshare[.]cloud | Suspected UNC5976-related domain |
| Domain | sharedfolders[.]org | Suspected UNC5976-related domain |
| Domain | drive[.]google[.]sharedfolders[.]org | Suspected UNC5976-related domain |
| Domain | eurcpa[.]org | Suspected UNC5976-related domain |
| Domain | drive[.]google[.]anticorruption[.]eurcpa[.]org | Suspected UNC5976-related domain |
| Domain | sharedfolders[.]app | Suspected UNC5976-related domain |
| Domain | drive[.]google[.]sharedfolders[.]app | Suspected UNC5976-related domain |
| Domain | usercontent[.]app | Suspected UNC5976-related domain |
| Domain | drive[.]google[.]usercontent[.]app | Suspected UNC5976-related domain |
| Domain | usercontent[.]online | Suspected UNC5976-related domain |
| Domain | drive[.]google[.]usercontent[.]online | Suspected UNC5976-related domain |
| Domain | fileshareapp[.]org | Net-new domain with similar content and a valid certificate |
| Domain | linkfileshare[.]net | Registration-pivot discovery |
| Domain | drive[.]google[.]linkfileshare[.]net | Registration-pivot discovery |
| Domain | supportnoreplay[.]com | Low-confidence registration pivot |
| Domain | security-forms[.]com | Low-confidence registration pivot |
| Domain | noreplaysupport[.]com | Low-confidence registration pivot |
| Domain | info-forms[.]com | Low-confidence registration pivot |
| CSS hash | 6971626bf83b92c4ceef538c8919ca17 | Shared CSS class hash associated with lookalike infrastructure |
| HTTP header hash | e4c0a20a5e50632867cd | Header hash used to identify similar fake Drive pages |
| Favicon MD5 | c66f20f2e39eb2f6a0a4cdbe0d955e5f | Distinctive fake Google Drive favicon hash |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…