Russian spies now targeting personal accounts of government, defense insiders – and their playbooks just got exposed
Lures include fake US State Department officials, WhatsApp messages, OAuth abuse, malware – and apparently, wine.

Image by Ramil Sitdikov | Reuters
- Russian spy groups are targeting personal accounts belonging to government, defense, academic, nonprofit, and think tank personnel.
- Attackers abuse legitimate authentication flows, including OAuth, app passwords, and device-code phishing, making malicious activity harder to spot.
- One group hijacks WhatsApp accounts, records fake calls, and deploys infostealers against Windows and Mac users.
- Google says the groups rapidly adapt their tactics, increasingly using commercial malware, AI, and encrypted messaging apps.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Google has exposed the playbooks of three Russian spy groups stepping up their espionage campaigns in recent months, linking the sophisticated spear-phishing attacks – involving everything from WhatsApp to wine – to the Kremlin-backed Midnight Blizzard.
The trio of distinct Russian state-backed attackers has been clocked targeting the personal accounts of government, defense, academic, nonprofit, and think-tank personnel across the US and Europe – all to steal secrets from Moscow’s apparent list of persons of interest, according to a new report from Google Threat Intelligence Group (GTIG) published Thursday.
These attacks are *extremely* targeted & rely heavily on social engineering and abuse real, legitimate features. They may involve multiple levels of social engineering across multiple applications. They'll adopt new tactics or tools mid operation and even follow up w/ targets,"said Gabby Roncone, Russian threat hunter at Google Threat Intelligence Group.
The three threat clusters - UNC6293, UNC7005, and UNC5976 – and their tactics have all the legacy hallmarks of a previous three-year-long phishing operation (2021-2024) carried out by the Russian-backed actors identified as ICE RELIC, also known by security insiders as Midnight Blizzard, APT29, or Cozy Bear.
Russian spies go after personal accounts
The groups share similar operational methodologies, overlap target industries and geographic regions, while relying heavily on “commercial residential proxies for post-compromise activity,” the research states.
Using encrypted messaging apps like WhatsApp for initial outreach, the trifecta also appears to share a penchant for the same tried-and-true phishing lures, including diplomatic event invitations, impersonating industry officials, and, for some reason, lots of talk about wine.
Still, the researchers found that each group had its own distinguishing attack patterns, behaviors, infrastructure, and lures. Rather than relying on obvious phishing pages, the groups often abuse legitimate authentication flows, encrypted messaging apps, convincing personas, and custom malware to get their hands on valuable accounts.
Like any surgical spear-phishing campaign, targeting can be extremely precise, with some of the campaigns going after fewer than five people at a time.
Google says it is exposing the tactics, techniques, and procedures (TTPs) of each so potential targets can quickly recognize suspicious behavior before falling victim.
Three groups, three playbooks
UNC7005: malware, AI, and encrypted messages
Who they target: UNC7005 targets individuals across sectors of strategic interest to Russia, including government, defense, academia, and think tanks.
Signature attack move: Microsoft device-code phishing and WhatsApp device hijacking backed by malware. Victims can be tricked into linking WhatsApp to an attacker-controlled device, while fake calls can secretly record their audio and video.
Google said the likely use of encrypted messaging applications for initial contact creates another problem for defenders, making malicious outreach harder to track and remediate.
UNC7005 has graduated to using malware-as-a-service (MaaS) and LLMs to support its operations, with Google noting that AI adoption is dramatically shortening the time attackers need "to develop and stage tooling for operations, enabling fast-turnaround operations with bespoke tools."
UNC7005 has also been linked to the recent Midnight Blizzard campaign hijacking hotel and conference WiFi portals to steal credentials and deliver malware.
Memorable tactic: The growing use of commercial malware and AI muddies attribution, making it harder for defenders to determine who is behind an attack based solely on the tools used.
UNC5976: targeting defense and aerospace
Who they target: UNC5976 has targeted individuals working in academia, aerospace and defense, government, and think tanks across Europe, along with academics and think tank personnel in the US.
Signature attack move: OAuth token theft via fake file-sharing pages and malicious Google Cloud projects. Victims are sent through a legitimate Google OAuth login before malicious scripts capture their authentication tokens.
The group created at least 12 new domains and related infrastructure within roughly three months as Google worked to disrupt its operations. GTIG says UNC5976 is now migrating away from Google infrastructure to other providers.
Memorable tactic: UNC5976 has also deployed a malicious Excel plugin dubbed HEADRUSH, which ultimately led to an HTML Application (HTA) downloader and may have targeted a Ukrainian aerospace and imaging company.
UNC6293: fake diplomats and authentication abuse
Who they target: UNC6293 primarily targets people working in academia, diplomacy, and nonprofits across Ukraine, Western Europe, and the US.
Signature attack move: App-password and OAuth phishing disguised as legitimate authentication. Attackers impersonate US State Department officials and trick targets into creating app passwords that can bypass 2FA.
More recently, victims have been asked to complete legitimate logins before handing over OAuth verification codes that give attackers access to their accounts.
Memorable tactic: UNC6293 campaigns are remarkably surgical, usually targeting fewer than five users at a time, with lures focused on diplomatic events, conferences, and meetings.
How to spot a Russian spy lure
Google warns that individuals working in sectors targeted by Russian groups should be particularly cautious of unexpected outreach from "unverified, though seemingly familiar or legitimate, personas or organizations."
For event invitations, Google recommends contacting organizers independently and warns against sourcing contact information from the invitation itself. Even when a message appears to come from a real person, researchers warn that the persona could simply be spoofed.
GTIG has also observed emails containing phishing links to attacker-created websites linked to command-and-control centers, which often use templates similar to those of legitimate sites.
Google also warns against using app passwords for identity verification.
Additionally, the research recommends revoking legacy app passwords linked to lost, stolen, or unused devices and removing any app password suspected of being connected to one of the campaigns.
For personal messaging apps, Google says to always use two-factor authentication and registration locks, regularly check for any unfamiliar linked devices, and use safety numbers or codes to verify contacts through a separate communication channel.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.