Google has uncovered the methods used by three Russian espionage groups that have stepped up their campaigns in recent months. The company linked their sophisticated phishing attacks, ranging from the use of WhatsApp to conversations about wine, to the Kremlin-backed hacking group Midnight Blizzard.
According to a new report from Google Threat Intelligence Group (GTIG), published on Thursday, researchers identified three separate groups linked to the Russian state. They targeted the personal accounts of people working in government, defense, academia, nonprofit organizations, and think tanks across the US and Europe. The attackers’ goal was to steal sensitive information from individuals of interest to Moscow.
“These attacks are extremely targeted and rely heavily on social engineering while also abusing real, legitimate features. They can involve multiple layers of social engineering across different apps. The attackers may change tactics or tools in the middle of an operation and even re-engage with their targets,” said Gabby Roncone, a researcher specializing in Russian cyber threats at Google Threat Intelligence Group.
The three threat clusters, UNC6293, UNC7005, and UNC5976, use tactics that bear the hallmarks of an earlier three-year phishing campaign that ran from 2021 to 2024. That campaign has been linked to Russia-backed hackers known as ICE RELIC, also referred to by cybersecurity researchers as Midnight Blizzard, APT29, or Cozy Bear.
The research notes that the groups use similar operational methods, with some overlap in both the sectors and geographic regions they target. After compromising accounts, the attackers also make extensive use of commercial residential proxies to conceal their activity.
For initial contact with potential victims, the hackers use encrypted messaging apps, including WhatsApp. All three groups also rely on similar, well-established phishing lures, such as invitations to diplomatic events, impersonating officials or representatives of organizations and, somewhat surprisingly, numerous conversations about wine.

However, researchers found that each group has its own distinctive attack patterns, behaviors, infrastructure, and lures. Instead of relying on obvious phishing pages, the attackers often abuse legitimate authentication mechanisms, use encrypted messaging apps, convincingly impersonate other people, and deploy custom-built malware to gain access to valuable accounts.
As with other highly targeted phishing campaigns, the selection of victims can be extremely precise. Some operations target fewer than five people at a time.
Google says it is disclosing the tactics, techniques, and procedures (TTPs) used by each group so that potential targets can recognize suspicious activity more quickly and prevent their accounts from being compromised.
UNC7005 uses malware, artificial intelligence, and encrypted messaging apps.
Who it targets: UNC7005 targets individuals across various sectors of strategic interest to Russia, including government, defense, academia, and think tanks.
How the attack works: One of UNC7005’s signature attack scenarios combines Microsoft device code phishing, WhatsApp account hijacking, and malware. Attackers can trick victims into linking their WhatsApp accounts to a device they control. During fake calls, the hackers may also secretly record the victim’s audio and video.

Google notes that using encrypted messaging apps for initial contact creates additional challenges for cybersecurity professionals, making it more difficult to track and disrupt malicious activity.
UNC7005 has also begun using Malware-as-a-Service (MaaS) and large language models (LLMs) to support its operations. According to Google, the use of artificial intelligence significantly reduces the time attackers need “to develop and prepare tools for operations, enabling them to quickly carry out attacks using custom-built tools.”
UNC7005 has also been linked to a recent Midnight Blizzard campaign in which hackers compromised Wi-Fi portals at hotels and conferences to steal credentials and distribute malware.

Key point: The growing use of commercial malware and artificial intelligence is making attack attribution more difficult. Cybersecurity professionals are finding it increasingly challenging to determine who is behind a particular operation based solely on the tools used by the attackers.
Who it targets: UNC5976 targets individuals working in academia, aerospace and defense, government agencies, and think tanks across Europe. In the US, the group has targeted academics and think tank staff.
How the attack works: One of UNC5976’s signature methods involves stealing OAuth tokens through fake file-sharing pages and malicious Google Cloud projects. Victims are redirected through a legitimate Google OAuth sign-in page, after which malicious scripts intercept their authentication tokens.

The group created at least 12 new domains and related infrastructure over roughly three months as Google worked to disrupt its operations. According to GTIG, UNC5976 is now gradually moving away from Google infrastructure and shifting to other providers.
Key point: UNC5976 also deployed a malicious Excel plugin called HEADRUSH, which ultimately triggered the download of an HTML Application (HTA). One possible target of the operation was a Ukrainian company working in the aerospace and imagery sector.
Who it targets: UNC6293 primarily targets people working in academia, diplomacy, and nonprofit organizations in Ukraine, Western Europe, and the US.
How the attack works: The group uses app-password and OAuth phishing disguised as legitimate authentication processes. The attackers impersonate US State Department officials and trick victims into creating app passwords that can allow them to bypass two-factor authentication (2FA).

Recently, attackers have begun asking victims to complete a legitimate sign-in process and then provide an OAuth verification code. Once they obtain the code, the hackers can gain access to the victim’s account.
Key point: UNC6293 campaigns are extremely narrowly targeted, typically focusing on fewer than five users at a time. Attackers use invitations to diplomatic events, conferences, and meetings as lures.
Google warns that people working in sectors of interest to Russian hacking groups should be particularly cautious about unexpected messages from unverified individuals or organizations, even if they appear familiar or entirely legitimate at first glance.
When receiving an invitation to a conference, meeting, or other event, Google recommends contacting the organizers independently to verify its authenticity. Contact details should be obtained separately rather than from the invitation itself. Even if a message appears to come from a real person, researchers warn that the attackers may simply be impersonating them.