GLOBSEC and Google: Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts

GLOBSEC and Google: Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts

Russian-Linked Cyber Espionage Campaign Expands OAuth and Phishing Tactics

A sophisticated cyber espionage campaign linked to Russian threat actors including UNC6293, a subcluster of ICE RELIC (APT29/Cozy Bear/Midnight Blizzard) is escalating account-compromise operations by abusing legitimate authentication workflows. The campaign combines OAuth phishing, device-code attacks, credential-harvesting infrastructure, and suspected Evilginx reverse-proxy setups to bypass multi-factor authentication (MFA) protections.

Key Tactics and Infrastructure

The attackers exploit trust in authentication processes rather than software vulnerabilities, tricking victims into authorizing attacker-controlled access. This method undermines MFA by convincing targets to complete legitimate logins before handing over tokens or OAuth permissions.

Lure Domains and Social Engineering

  • foreignrelations[.]us and dosportal[.]app were identified as OAuth phishing lures, with historical WHOIS data linking them to the registrant email given956[@]2200freefonts[.]com, which also registered internationalaffairsportal[.]us and stateaffairs[.]us.
  • Archived content on foreignrelations[.]us referenced a Council on Foreign Relations article, while other domains reused web templates and meta tags to mimic trusted diplomatic and policy content.
  • Evilginx-style behavior was observed on stateaffairs[.]us subdomains between January 13 and February 2, 2026, redirecting users to legitimate U.S. Department of State sites to capture session credentials.

Additional Threat Clusters

  • UNC7005, tracked separately due to weaker operational security, used Microsoft device-code phishing and targeted WhatsApp accounts via fake event invitations (e.g., a spoofed GLOBSEC Forum 2026 lure hosted on my-invite[.]org).
  • UNC5976 focused on Google-themed OAuth phishing, including drive[.]google[.]verify-drive[.]com, which mimicked Google Drive with a decoy login page. A shared favicon hash (c66f20f2e39eb2f6a0a4cdbe0d955e5f) linked multiple domains, aiding detection.

Targets and Impact

The campaign primarily targets academia, government, aerospace, defense, and think tanks across Europe and the U.S.. By blending polished decoy sites, legitimate redirects, and OAuth prompts, the attackers reduce the likelihood of detection before account access is compromised.

Indicators of Compromise (IOCs)

  • IPs: 151.236.15[.]213, 185.158.250[.]155
  • Domains: fllefolder[.]com, sharefolders[.]org, formshare[.]cloud, sharedfolders[.]org
  • Subdomains: drive[.]google[.]sharefolders[.]org, drive[.]google[.]formshare[.]cloud

The campaign highlights the growing threat of adversary-in-the-middle (AitM) phishing frameworks, which exploit trust in identity services rather than technical flaws. Organizations are advised to monitor for unexpected OAuth consent requests, device-code prompts, and anomalous token usage to mitigate exposure.

Source: https://gbhackers.com/russian-cyber-espionage/

Google Cloud Security cybersecurity rating report: https://www.rankiteo.com/company/googlecloudsecurity

GLOBSEC cybersecurity rating report: https://www.rankiteo.com/company/globsec

"id": "GOOGLO1787819408",
"linkid": "googlecloudsecurity, globsec",
"type": "Cyber Attack",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': ['Education',
                                     'Government',
                                     'Aerospace & Defense',
                                     'Research'],
                        'location': ['Europe', 'U.S.'],
                        'type': ['Academia',
                                 'Government',
                                 'Aerospace',
                                 'Defense',
                                 'Think tanks']}],
 'attack_vector': ['OAuth phishing',
                   'Device-code attacks',
                   'Credential-harvesting infrastructure',
                   'Evilginx reverse-proxy setups'],
 'data_breach': {'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Session credentials',
                                              'Authentication tokens',
                                              'Personally identifiable '
                                              'information']},
 'description': 'A sophisticated cyber espionage campaign linked to Russian '
                'threat actors including UNC6293, a subcluster of ICE RELIC '
                '(APT29/Cozy Bear/Midnight Blizzard), is escalating '
                'account-compromise operations by abusing legitimate '
                'authentication workflows. The campaign combines OAuth '
                'phishing, device-code attacks, credential-harvesting '
                'infrastructure, and suspected Evilginx reverse-proxy setups '
                'to bypass multi-factor authentication (MFA) protections.',
 'impact': {'data_compromised': True, 'identity_theft_risk': True},
 'initial_access_broker': {'entry_point': ['OAuth phishing lures',
                                           'Fake event invitations'],
                           'high_value_targets': ['Academia',
                                                  'Government',
                                                  'Aerospace',
                                                  'Defense',
                                                  'Think tanks']},
 'lessons_learned': 'The campaign highlights the growing threat of '
                    'adversary-in-the-middle (AitM) phishing frameworks, which '
                    'exploit trust in identity services rather than technical '
                    'flaws.',
 'motivation': 'Cyber espionage',
 'post_incident_analysis': {'root_causes': 'Exploitation of trust in '
                                           'authentication processes (OAuth, '
                                           'MFA bypass) and social engineering '
                                           'via polished decoy sites.'},
 'recommendations': 'Organizations are advised to monitor for unexpected OAuth '
                    'consent requests, device-code prompts, and anomalous '
                    'token usage to mitigate exposure.',
 'references': [{'source': 'Cyber Incident Description'}],
 'response': {'enhanced_monitoring': 'Monitor for unexpected OAuth consent '
                                     'requests, device-code prompts, and '
                                     'anomalous token usage'},
 'threat_actor': ['UNC6293 (subcluster of ICE RELIC/APT29/Cozy Bear/Midnight '
                  'Blizzard)',
                  'UNC7005',
                  'UNC5976'],
 'title': 'Russian-Linked Cyber Espionage Campaign Expands OAuth and Phishing '
          'Tactics',
 'type': 'Cyber Espionage',
 'vulnerability_exploited': 'Legitimate authentication workflows (OAuth, MFA '
                            'bypass)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.