That approach can bypass the protection users associate with multifactor authentication. A victim may not be handing over a password at all; they may be approving an OAuth application, creating an app password or linking a new device. In each case, the victim’s action can give an attacker a legitimate-looking path into an account.
UNC6293 reportedly impersonated U.S. State Department officials and other trusted contacts. The lures were designed to persuade targets to create and disclose application-specific passwords, which can provide account access outside a normal second-factor prompt. GTIG also described OAuth-consent phishing, in which attackers seek authorized tokens rather than directly stealing a password.
GTIG assessed with moderate confidence that UNC6293 was an initial-access subcluster of ICE RELIC, Google’s name for the actor formerly known as APT29.
UNC7005 used a broader set of evolving techniques, including:
The cluster’s techniques and infrastructure differed from UNC6293’s, which is why GTIG tracks them separately despite their overlapping targeting and reliance on legitimate authentication flows.
UNC5976 reportedly focused on military, aerospace and defense-related personnel and organizations, including targets connected to Ukraine and Armenia. Its phishing activity sought authorization through OAuth to access victims’ accounts or data.
GTIG assessed with high confidence that the overall activity had a Russian nexus. That is an attribution assessment, not a claim that every operational detail or cluster relationship is proven with equal certainty.
The available reporting also describes possible links between some of the activity and ICE RELIC/APT29. GTIG’s assessment connecting UNC6293 to ICE RELIC was moderate confidence, while the clusters continue to be tracked separately because their tradecraft and infrastructure are not identical.
Multifactor authentication can still be defeated when an attacker manipulates a user into approving the wrong action. An unexpected OAuth consent screen, app-password request or WhatsApp linking code may represent account takeover even if no password is stolen.
The practical lesson is to treat authentication prompts as transactions that require verification—not as automatically safe steps simply because they appear inside a familiar service.
GTIG’s guidance emphasizes slowing down the workflow attackers are trying to accelerate:
For people working in sensitive sectors, the most important habit is simple: a familiar brand, a real login page or a genuine authentication feature does not prove that the request is legitimate. The request itself—and the person or organization that initiated it—must also be verified.