Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia
Because these attacks often target personal rather than corporate accounts, organizations have a visibility gap that makes detecting breaches harder. This increases the risk of sensitive data theft for individuals in diplomatic, defense, and academic sectors.
- UNC6293, a sub-cluster of ICE RELIC (formerly APT29), conducted app password and OAuth phishing campaigns impersonating the U.S. Department of State.
- UNC7005 conducted device code phishing, hospitality captive portal redirects, and deployed MaaS infostealers including VIDAR and ATOMIC as well as LLM-generated CHERRYPIE malware.
- UNC5976 abused cloud infrastructure for OAuth token theft and deployed the HEADRUSH malicious Excel plugin against Ukrainian aerospace and defense organizations.
- Google took actions to disable malicious cloud projects, add infrastructure to the Safe Browsing blocklist, and coordinate disruption with industry and government partners.