Cyber Security News

Russian Hackers Use Fake Google Drive and Diplomatic Lures to Steal Online Account

Russian-linked operators are using fake cloud-storage pages and diplomatic themes to trick targets into giving away access to online accounts. The following article body is 650 words, excluding the IoC table.

Russian cyber espionage campaigns are using convincing Google Drive pages and diplomatic invitations to take over online accounts.

Instead of relying on a malicious download, the operators steer targets into legitimate sign-in processes and capture the access they need.

The activity has focused on people in academia, think tanks, government-linked bodies, and defense-related organizations in Europe and the United States.

Emails and webpages imitate familiar services, events, or institutions, making a request to view a document or register for a meeting appear routine.

Analysts at Validin identified further infrastructure around the campaigns after examining historical DNS records, website responses, certificates, registration data, and visual page features.

Validin said in a report shared with Cyber Security News (CSN) that their work expands on reporting by Google Threat Intelligence Group, which tracked the activity under the clusters UNC6293, UNC7005, and UNC5976. The impact can be serious even when a victim never installs traditional malware.

WhatsApp device code phishing lure (Source – Validin)

A stolen consent token, device code, app password, or active browser session can give an intruder access to email, cloud files, contacts, and trusted conversations, during routine work and potentially exposing sensitive diplomatic correspondence and external partners.

Russian Hackers Use Fake Google Drive

The UNC5976 cluster used a Google Drive lookalike domain in an OAuth phishing operation. Validin captured the page with the title “My Drive – Google Drive,” a small detail designed to reassure a recipient who expected to open or share a file.

OAuth phishing abuses a real authorization process rather than simply asking for a password on a crude fake form. A target can be sent to a genuine provider sign-in page, then prompted to approve an attacker-controlled application.

That approval may hand over tokens that let attackers reach account data without needing the password again. The researchers found similar hosting and content patterns across additional lookalike domains, showing how quickly an operation can rotate its web infrastructure.

This approach aligns with earlier reporting on Russian hackers abuse OAuth, where tailored themes were used to push targets toward account takeovers.

Fake login prompt (Source – Validin)

Validin also recorded a distinctive fake Drive favicon and matching page characteristics that helped narrow a much larger set of possible sites.

Such technical traces matter because names alone are unreliable: attackers can register and abandon domains rapidly, while copied page templates and server behavior can expose a broader campaign.

Diplomatic Lures Broaden the Campaign

UNC6293 used foreign policy-themed web lures to support OAuth phishing. The material copied content connected to the Council on Foreign Relations, while related names referenced international affairs and state matters, giving the operation a credible policy-focused appearance.

The campaign also showed signs of proxy-based phishing. Several campaign-linked subdomains briefly redirected visitors to legitimate U.S. State Department and Washington Ballet pages.

Validin assessed the responses as possible Evilginx configurations, a technique associated with live interception of sign-in sessions.

A separate cluster, UNC7005, used fake invitations to target Microsoft and WhatsApp accounts through device-code phishing. One lure promoted a supposed Prague event and changed its branding and deadline over time.

A domain hosted on pages[.]dev (Source – Validin)

The tactic reflects the growing use of familiar account-linking screens, also seen in Russian hackers spoof European events, to make urgent authentication requests feel legitimate.

Combining historical DNS, page captures, certificate data, and registration records can uncover related infrastructure.

The researchers caution that pivots need verification, since shared hosting, expired DNS, and copied web content can create misleading overlaps.

Organizations should treat unexpected Drive shares, conference invitations, and device-linking requests as potential account-theft attempts, particularly when they arrive from an unfamiliar domain.

Users should independently open the service instead of following the message link, review an OAuth application’s requested permissions, and report suspicious pages.

Security teams should monitor unusual consent grants and session activity, while phishing-resistant sign-in methods can reduce exposure to proxy-style attacks described in Evilginx AiTM phishing attacks.

The technical indicators associated with this activity, including newly identified related infrastructure, appear in the table below for defensive monitoring and blocking.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
Domainforeignrelations[.]usUNC6293 OAuth phishing lure
Domaindosportal[.]appUNC6293 OAuth phishing lure
Domaininternationalaffairsportal[.]usSuspected UNC6293-related domain
Domainstateaffairs[.]usSuspected UNC6293-related domain; possible proxy-phishing activity
Domainthe-washington-ballet[.]comSuspected UNC6293-related domain; possible proxy-phishing activity
IP address151.236.15[.]213Possible origin IP for UNC6293-related infrastructure
IP address185.158.250[.]155Possible origin IP for UNC6293-related infrastructure
Email addressgiven956[@]2200freefonts[.]comRegistrant email associated with suspected UNC6293 domains
Domain2200freefonts[.]comDomain used in the registrant email; not attributed to UNC6293
Domainmy-invite[.]orgUNC7005 phishing infrastructure
IP address104.194.159[.]150Historical resolution for my-invite[.]org
Domainms365-live[.]comRelated infrastructure overlap
Domainstatistic-ms[.]liveUNC7005 redirect infrastructure
URLhttps[:]//ad-g[.]org/loginLogin page reached through statistic-ms[.]live
Domainad-g[.]orgUNC7005-related phishing infrastructure
Domaindrive[.]google[.]verify-drive[.]comUNC5976 OAuth phishing lure
Domainverify-drive[.]comRelated UNC5976 infrastructure
IP address93.127.160[.]28Historical hosting IP for verify-drive[.]com
Domainfllefolder[.]comSuspected UNC5976-related domain
Domainsharefolders[.]orgSuspected UNC5976-related domain
Domaindrive[.]google[.]sharefolders[.]orgSuspected UNC5976-related domain
Domainformshare[.]cloudSuspected UNC5976-related domain
Domaindrive[.]google[.]formshare[.]cloudSuspected UNC5976-related domain
Domainsharedfolders[.]orgSuspected UNC5976-related domain
Domaindrive[.]google[.]sharedfolders[.]orgSuspected UNC5976-related domain
Domaineurcpa[.]orgSuspected UNC5976-related domain
Domaindrive[.]google[.]anticorruption[.]eurcpa[.]orgSuspected UNC5976-related domain
Domainsharedfolders[.]appSuspected UNC5976-related domain
Domaindrive[.]google[.]sharedfolders[.]appSuspected UNC5976-related domain
Domainusercontent[.]appSuspected UNC5976-related domain
Domaindrive[.]google[.]usercontent[.]appSuspected UNC5976-related domain
Domainusercontent[.]onlineSuspected UNC5976-related domain
Domaindrive[.]google[.]usercontent[.]onlineSuspected UNC5976-related domain
Domainfileshareapp[.]orgNet-new domain with similar content and a valid certificate
Domainlinkfileshare[.]netRegistration-pivot discovery
Domaindrive[.]google[.]linkfileshare[.]netRegistration-pivot discovery
Domainsupportnoreplay[.]comLow-confidence registration pivot
Domainsecurity-forms[.]comLow-confidence registration pivot
Domainnoreplaysupport[.]comLow-confidence registration pivot
Domaininfo-forms[.]comLow-confidence registration pivot
CSS hash6971626bf83b92c4ceef538c8919ca17Shared CSS class hash associated with lookalike infrastructure
HTTP header hashe4c0a20a5e50632867cdHeader hash used to identify similar fake Drive pages
Favicon MD5c66f20f2e39eb2f6a0a4cdbe0d955e5fDistinctive fake Google Drive favicon hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago