<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts]]></title><description><![CDATA[<p dir="auto">Three distinct suspected Russian cyber espionage clusters are actively abusing legitimate Google OAuth flows and the WhatsApp linking feature to compromise accounts belonging to academics, defense professionals, and government staff across Europe, with similar targeting observed against academia and think tanks in the U.S. The threat actors involved are tracked as <strong>UNC6293</strong>, <strong>UNC7005</strong>, and <strong>UNC5976</strong>.</p>
<p dir="auto">These groups are relying on persistent, adaptive techniques that exploit user trust in standard authentication procedures rather than deploying novel malware. By mimicking legitimate login prompts and abusing account-linking processes, the actors can hijack accounts without triggering typical security alerts. The focus on high-value individuals in geopolitically sensitive sectors suggests a concerted espionage campaign aimed at intelligence collection.</p>
<p dir="auto">Key characteristics of the campaigns include:</p>
<ul>
<li>Abuse of Google OAuth to request excessive permissions or device-bound tokens, allowing persistent access even if passwords are changed.</li>
<li>Manipulation of the WhatsApp web-linking feature to silently bind an attacker-controlled device to the victim's account, enabling real-time message interception.</li>
<li>Heavy use of social engineering to initiate the authentication flow, often through convincing phishing lures tailored to the target's research or policy focus.</li>
<li>Active monitoring of victim inboxes to intercept multi-factor authentication (MFA) prompts or recovery codes.</li>
</ul>
<p dir="auto">The threat actors are noted for their ability to adapt quickly, shifting infrastructure and changing tactics when initial access attempts fail. The operational tempo suggests a highly organized effort requiring significant operational security discipline.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Is your organization currently requiring additional verification for any unexpected OAuth or device-linking requests, or have you observed similar phishing lures targeting your user base?</p>
]]></description><link>https://xploitlk.com/topic/68/suspected-russian-hackers-abuse-google-oauth-and-whatsapp-linking-to-hijack-accounts</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:35:50 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/68.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 23 Aug 2026 08:30:22 GMT</pubDate><ttl>60</ttl></channel></rss>