Actor Profile

UNC6293, UNC7005, and UNC5976 are three distinct suspected Russian cyber espionage threat clusters conducting persistent account compromise operations. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear and Midnight Blizzard), first detailed in June 2025. UNC7005 (aka Storm-2945), identified in February 2026, is also believed to be related to a sub-group within Ice Relic focused on initial access operations. UNC5976 has been active since at least March 2026. These clusters are motivated by intelligence collection targeting Western government, defense, academic, and think tank personnel of interest to the Kremlin. Both UNC6293 and UNC7005 rely on commercial residential proxies for post-compromise activity and conduct highly selective, small-scope phishing campaigns targeting fewer than five users at a time.

TTPs (Tactics, Techniques, Procedures)

The clusters employ sophisticated social engineering and authentication abuse techniques. UNC6293 conducts app password phishing by impersonating State Department officials with diplomatic-themed lures and conferences, and as of June 2026 performs OAuth phishing requesting targets to share full URLs or verification codes after legitimate external provider logins. UNC5976 automates OAuth token collection by purchasing file-sharing-themed domains, hosting fake file sharing pages with "Continue with Google" pop-ups that redirect to legitimate Google OAuth login pages, then retrieving authentication tokens via malicious scripts hosted on Google Cloud project URLs. UNC5976 also deploys HEADRUSH, a rogue Excel plugin delivering HTA downloaders via fake Ukrainian research institute domains. UNC7005 employs app password phishing, device code phishing targeting Microsoft and WhatsApp accounts, and WhatsApp linking attacks using wine-related and diplomatic event lures (SPIKEDWINE operations). The WhatsApp technique prompts targets to provide phone numbers to create legitimate device link requests, displaying QR codes and linking instructions to hijack accounts.

Targets & Patterns

The clusters target individuals in academia, aerospace and defense, government, and think tanks across Europe and the U.S., with additional focus on Ukraine and Armenia. UNC6293 targets fewer than five users per campaign, impersonating State Department officials. UNC5976's operational focus centers on military, aerospace, defense industrial base, and NGOs/think tanks, with geographic targeting concentrated on Ukraine and Armenia; specific targeting includes a Ukrainian aerospace and imaging company. UNC7005 mainly targets academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the U.S. The targeting pattern reflects intelligence collection priorities aligned with Kremlin interests, focusing on individuals with access to sensitive diplomatic, defense, and policy information. The highly selective, small-scope approach suggests careful victim selection based on intelligence value rather than broad opportunistic compromise.

Historical Context

UNC6293 was first detailed by Google and Citizen Lab in June 2025, when it was attributed to campaigns abusing Google application specific passwords. The cluster has continued phishing operations since then, with activity highlighted by Volexity in December 2025 and ongoing through June 2026. UNC7005 was identified in February 2026 and has conducted operations through at least June 2026. UNC5976 has been active since at least March 2026, creating at least 12 new domains and related infrastructure between March and the time of reporting (August 2026), all of which were disrupted by Google, prompting the actor to pivot to other cloud providers. The use of wine-related lures by UNC7005 connects to Ice Relic attack patterns dating back to April 2023, with some aspects codenamed SPIKEDWINE by Zscaler. The HEADRUSH malware was discovered in April 2026. Both UNC6293 and UNC7005 are assessed as sub-groups within Ice Relic (APT29/Cozy Bear/Midnight Blizzard) focused on initial access operations.

Defensive Recommendations

  • Monitor for OAuth consent grant anomalies, particularly authorization requests to newly created or suspicious cloud projects with file-sharing-themed domain names, and implement OAuth application allowlisting policies
  • Detect WhatsApp device linking abuse by educating users on legitimate linking workflows and warning against unsolicited QR code or linking code requests, especially those claiming to enable secure calls or document sharing
  • Implement conditional access policies requiring phishing-resistant MFA (FIDO2/WebAuthn) for high-value accounts in government, defense, academia, and think tank sectors to prevent app password and device code phishing
  • Monitor for Excel plugin installations from untrusted sources and block HTA file execution via application control policies to mitigate HEADRUSH-style delivery mechanisms
  • Analyze authentication logs for device code flow abuse patterns, including multiple device code requests from single users and authentication attempts following diplomatic event or conference-themed email lures, particularly those with wine-related themes

---

# Geopolitical Context

Geopolitical Context

Three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—have been observed conducting persistent account compromise operations against high-value targets in academia, aerospace, defense, government institutions, and think tanks across Europe and the United States. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also known as Cozy Bear and Midnight Blizzard), a group widely attributed to Russia's Foreign Intelligence Service (SVR). The campaigns demonstrate sophisticated social engineering tradecraft, abusing legitimate authentication mechanisms including Google OAuth flows, Microsoft device code phishing, and WhatsApp device linking to hijack personal accounts. The operations appear consistent with intelligence collection priorities aligned with Russian state interests, particularly targeting individuals and organizations involved in defense policy, diplomatic affairs, and Ukraine-related research. The use of diplomatic event lures, impersonation of U.S. State Department officials, and targeting of Ukrainian aerospace entities reflects operational focus areas consistent with Kremlin intelligence requirements during the ongoing Russia-Ukraine conflict.

State Actor Alignment

UNC6293 is assessed by Google Threat Intelligence Group to be a sub-cluster of Ice Relic (APT29), a threat actor widely attributed to Russia's Foreign Intelligence Service (SVR) by the U.S. government and allied intelligence agencies. Both UNC6293 and UNC7005 are believed to be related to a sub-group within Ice Relic focused on initial access operations. The targeting patterns—including impersonation of U.S. State Department officials, use of diplomatic conference lures, and focus on Ukrainian defense and aerospace sectors—are consistent with Russian foreign intelligence collection priorities. UNC5976's operational focus on military, aerospace, defense industrial base entities, and geographic concentration on Ukraine and Armenia further aligns with Russian strategic interests in the region. While Google frames these as "suspected Russian" clusters, the technical lineage to APT29/SVR, combined with targeting consistent with state-level intelligence requirements, strongly suggests coordination with or direction by Russian state security apparatus. These operations would fall under existing U.S. and allied sanctions frameworks targeting Russian intelligence entities, though attribution of specific clusters to formal organizational units remains an intelligence assessment rather than public attribution.

Business Impacty pro region

The campaigns have significant implications for transatlantic security and information integrity. Targeting of European and U.S. government, defense, and think tank personnel represents a persistent threat to policy deliberation processes, particularly regarding Ukraine support and NATO posture. The focus on Ukrainian aerospace and research institutions directly supports Russian military intelligence requirements in the ongoing conflict. The abuse of trusted platforms—Google, Microsoft, WhatsApp—to conduct espionage operations undermines confidence in authentication mechanisms that underpin digital collaboration across allied governments and research communities. The selective, low-volume nature of the campaigns (often fewer than five targets at a time) suggests high-value intelligence collection rather than broad information operations, indicating that compromised accounts may provide access to sensitive policy discussions, defense research, or diplomatic communications. For European allies, the persistent targeting of diplomatic and defense sectors reinforces the need for enhanced account security protocols and awareness training, particularly for personnel engaged in Ukraine-related policy work or defense industrial cooperation. The geographic spread across Western Europe and concentration on transatlantic institutions suggests an intent to map and penetrate allied decision-making networks.

Forecast

If these clusters maintain their current operational tempo and adaptive tradecraft, continued account compromise attempts against high-value targets in allied governments, defense sectors, and policy communities are highly likely through at least the remainder of 2026. The threat actors' demonstrated ability to pivot infrastructure and techniques—such as UNC5976's shift away from Google infrastructure following disruption—suggests resilience and sustained resource investment consistent with state sponsorship. If platform providers continue to disrupt infrastructure and improve detection of authentication abuse, the clusters may increasingly shift to alternative platforms or develop novel social engineering approaches, potentially including abuse of emerging collaboration tools or encrypted messaging services. Organizations and individuals in the targeted sectors should anticipate continued phishing attempts leveraging diplomatic event themes, particularly those related to Ukraine policy, NATO activities, or transatlantic defense cooperation. If geopolitical tensions between Russia and Western allies remain elevated, the intelligence value of these targets will likely sustain operational prioritization by Russian services, making persistent targeting probable. Enhanced multi-factor authentication, hardware security keys, and user awareness of device linking risks will be critical mitigations, though determined state actors may continue to achieve selective compromises through sophisticated social engineering.