Google just mapped three separate Russian hacking crews going after journalists and researchers
Google's Threat Intelligence Group published a deep dive on three distinct Russian-nexus clusters that have spent the past year phishing academics, diplomats, defense researchers, and Russia critics, not through malware-laden attachments but by abusing legitimate auth flows: app passwords, OAuth consent screens, device-code logins, even WhatsApp device linking. One cluster, UNC7005, is the same group tied to those hotel captive-portal redirects Reliaquest and Microsoft flagged in July, and it's now been caught spoofing a Finnish defense-industry group and NATO-adjacent conference invites to harvest Google OAuth tokens.
What makes this worth reading closely if you're a likely target yourself: the report walks through exactly what these lures look like at each stage, fake conference registration pages, "verification code" prompts, WhatsApp linking flows dressed up as secure calls, so you can actually recognize them mid-attack rather than after the fact. It also includes a full IOC list (domains, file hashes) if you want to check your own exposure.















