Washington Ballet: Russian Hackers Use Fake Google Drive and Diplomatic Lures to Steal Online Account

Washington Ballet: Russian Hackers Use Fake Google Drive and Diplomatic Lures to Steal Online Account

Russian Cyber Espionage Campaigns Exploit Fake Cloud Storage and Diplomatic Lures

Russian-linked cyber espionage groups are leveraging convincing fake Google Drive pages and diplomatic-themed phishing lures to compromise online accounts across high-value targets. The campaigns, tracked under clusters UNC6293, UNC7005, and UNC5976, primarily target academia, think tanks, government-linked organizations, and defense sectors in Europe and the United States.

Instead of relying on traditional malware, attackers manipulate legitimate authentication processes such as OAuth phishing and device-code phishing to capture access tokens, session cookies, or app passwords. These stolen credentials grant intruders persistent access to email, cloud storage, contacts, and sensitive communications, including diplomatic correspondence.

Key Tactics and Infrastructure

  1. Fake Google Drive Pages (UNC5976)

    • Attackers used lookalike domains (e.g., drive[.]google[.]verify-drive[.]com) mimicking Google Drive’s interface, complete with a deceptive favicon and page title ("My Drive – Google Drive").
    • OAuth phishing tricks victims into approving malicious applications, granting attackers long-term access without needing passwords. Researchers identified 18+ related domains sharing similar hosting patterns, CSS hashes, and HTTP headers.
  2. Diplomatic and Policy-Themed Lures (UNC6293)

    • Phishing emails and webpages impersonated institutions like the Council on Foreign Relations, using domains such as foreignrelations[.]us and internationalaffairsportal[.]us.
    • Some subdomains briefly redirected to legitimate sites (e.g., U.S. State Department, Washington Ballet), likely via Evilginx proxy-based phishing to intercept live login sessions.
  3. WhatsApp and Microsoft Device-Code Phishing (UNC7005)

    • Fake invitations, including a Prague event lure, prompted targets to authenticate via Microsoft or WhatsApp device-code flows. Domains like my-invite[.]org and ms365-live[.]com were used to host these attacks.

Technical Traces and Attribution

Analysts at Validin expanded on Google Threat Intelligence Group’s findings by correlating DNS records, TLS certificates, registration data, and visual page features to uncover additional infrastructure. Shared indicators such as a distinctive favicon hash (MD5: c66f20f2e39eb2f6a0a4cdbe0d955e5f) and CSS class hashes helped link disparate domains to the same campaigns.

While attackers rapidly rotate domains, overlapping hosting IPs (e.g., 151.236.15[.]213, 185.158.250[.]155) and registration patterns (e.g., given956[@]2200freefonts[.]com) provided further attribution clues. However, researchers cautioned that shared hosting and expired DNS records can create misleading overlaps.

Impact and Scope

The campaigns highlight a shift toward credential-harvesting over malware, exploiting trust in familiar services. Successful compromises could expose sensitive documents, internal communications, and third-party contacts, with potential ripple effects across diplomatic and defense networks. The use of OAuth abuse and proxy-based phishing underscores the sophistication of these operations, making detection challenging for traditional security tools.

Source: https://cybersecuritynews.com/hackers-use-fake-google-drive/

Washington Ballet TPRM report: https://www.rankiteo.com/company/the-washington-institute-for-near-east-policy

"id": "the1787827161",
"linkid": "the-washington-institute-for-near-east-policy",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Education',
                        'location': ['Europe', 'United States'],
                        'type': 'Academia'},
                       {'industry': 'Research/Policy',
                        'location': ['Europe', 'United States'],
                        'type': 'Think Tanks'},
                       {'industry': 'Government',
                        'location': ['Europe', 'United States'],
                        'type': 'Government-Linked Organizations'},
                       {'industry': 'Defense',
                        'location': ['Europe', 'United States'],
                        'type': 'Defense Sectors'}],
 'attack_vector': ['OAuth Phishing',
                   'Device-Code Phishing',
                   'Proxy-Based Phishing (Evilginx)'],
 'data_breach': {'personally_identifiable_information': 'Likely (via '
                                                        'compromised accounts)',
                 'sensitivity_of_data': 'High (diplomatic and defense-related)',
                 'type_of_data_compromised': ['Email',
                                              'Cloud storage',
                                              'Contacts',
                                              'Sensitive communications',
                                              'Diplomatic correspondence']},
 'description': 'Russian-linked cyber espionage groups are leveraging '
                'convincing fake Google Drive pages and diplomatic-themed '
                'phishing lures to compromise online accounts across '
                'high-value targets. The campaigns, tracked under clusters '
                'UNC6293, UNC7005, and UNC5976, primarily target academia, '
                'think tanks, government-linked organizations, and defense '
                'sectors in Europe and the United States. Attackers manipulate '
                'legitimate authentication processes such as OAuth phishing '
                'and device-code phishing to capture access tokens, session '
                'cookies, or app passwords, granting persistent access to '
                'email, cloud storage, contacts, and sensitive communications.',
 'impact': {'data_compromised': ['Email',
                                 'Cloud storage',
                                 'Contacts',
                                 'Sensitive communications',
                                 'Diplomatic correspondence'],
            'identity_theft_risk': 'High (access to PII via compromised '
                                   'accounts)',
            'operational_impact': 'Persistent unauthorized access to sensitive '
                                  'data',
            'systems_affected': ['Online accounts', 'Cloud services']},
 'initial_access_broker': {'backdoors_established': 'Persistent access via '
                                                    'stolen tokens/session '
                                                    'cookies',
                           'entry_point': ['Fake Google Drive pages',
                                           'Diplomatic-themed phishing lures',
                                           'WhatsApp/Microsoft device-code '
                                           'phishing'],
                           'high_value_targets': ['Academia',
                                                  'Think tanks',
                                                  'Government-linked '
                                                  'organizations',
                                                  'Defense sectors']},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'The campaigns highlight a shift toward '
                    'credential-harvesting over malware, exploiting trust in '
                    'familiar services. OAuth abuse and proxy-based phishing '
                    'make detection challenging for traditional security '
                    'tools.',
 'motivation': 'Espionage, access to sensitive diplomatic and defense '
               'communications',
 'post_incident_analysis': {'corrective_actions': ['Implement stricter OAuth '
                                                   'app approval policies',
                                                   'Deploy advanced phishing '
                                                   'detection tools',
                                                   'Conduct regular security '
                                                   'awareness training'],
                            'root_causes': ['Exploitation of trust in '
                                            'legitimate authentication '
                                            'processes',
                                            'Use of lookalike domains and '
                                            'proxy-based phishing',
                                            'Lack of user awareness on '
                                            'OAuth/device-code phishing '
                                            'risks']},
 'recommendations': ['Enhance monitoring for OAuth phishing and device-code '
                     'phishing attempts',
                     'Implement multi-factor authentication (MFA) for all '
                     'critical accounts',
                     'Educate users on recognizing phishing lures and fake '
                     'authentication pages',
                     'Monitor for unusual access patterns in cloud services',
                     'Collaborate with threat intelligence providers to track '
                     'emerging infrastructure'],
 'references': [{'source': 'Validin'},
                {'source': 'Google Threat Intelligence Group'}],
 'threat_actor': 'Russian-linked cyber espionage groups (UNC6293, UNC7005, '
                 'UNC5976)',
 'title': 'Russian Cyber Espionage Campaigns Exploit Fake Cloud Storage and '
          'Diplomatic Lures',
 'type': 'Cyber Espionage',
 'vulnerability_exploited': ['Legitimate authentication processes',
                             'Trust in familiar services']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.