An alarm has been raised by Google over the hijacking of Microsoft and WhatsApp accounts. This is not done with obvious fakes but by piggybacking on the real thing. Suspected Russian cyber espionage groups are said to be abusing the OAuth flow and device linking to get around user caution in their targeting of key sectors across Europe and the US.
The deception works because the pages and prompts are made to look entirely authentic, so victims feel they have nothing to worry about. In fact, the Google Threat Intelligence Group says that tokens, app permissions and device codes are being intercepted in the course of the process, allowing an attacker to take hold of an account without the need to steal a password.
What is new in these attacks
There is a trust people put in the sign-in experience and three actor groups are leaning on it, reports Google. Rather than resorting to some crude forgery, the victim is directed to an actual authentication page where the system itself is put to bad use.
UNC6293, UNC7005 and UNC5976 are the groups in question. They will mix in app passwords, OAuth and device linking with the odd fake login page. It is a combination that makes for an operation which is difficult to detect and one the user may well cooperate with without realising it.
How WhatsApp takeovers happen
Device-code phishing is the method of choice for UNC7005 when it comes to Microsoft and WhatsApp, according to Google. One might be lured by an invitation to a diplomatic event or a high-level meeting, which then funnels them to a website with very convincing branding.
Once there, a person is asked for his or her phone number and presented with what appears to be a legitimate WhatsApp QR code for device linking. Should the victim oblige, the attacker is able to link his own device to the account and quietly make off with the data and conversations.
It does not end with the takeover. Google has come across phishing sites that nudge the victim into a false call or file download. We have seen cases where the page’s malicious code can access the camera and microphone to record audio and video for the attackers.
Microsoft and Google accounts under pressure
The same device-code ruse is applied to Microsoft. Google says UNC7005 has put together sites in the image of certain organisations or events and then put forward an identity verification step as a means to harvest device codes and tie in a session under the attacker’s control.
Then there is the high-impact angle of OAuth. A group has put together file-sharing lookalikes to coax a user to continue with Google. Once on the real login page they try to get the authentication token; with it, the password becomes irrelevant to gaining access.
A simple visual check will not suffice anymore. The surrounding flow can be hostile even if the login page is for all intents and purposes genuine, and that runs counter to the instincts many have as to what is safe.
Who is being targeted and who is behind it
Those in the crosshairs are from think tanks, academia, defence and government, mostly in the US and Europe. Any account that holds potential intelligence value is of prime interest to the attackers, per Google.
As for the source, Google has little doubt that UNC6293, UNC7005 and UNC5976 are of Russian origin. The conclusion is drawn from the technical methods and the kind of themes found in the phishing messages throughout the campaigns.
What you should do now
The advice from Google is plain: be wary of red flags in the form of unexpected prompts, even in the middle of a real sign-in. There is no reason to approve a device link or login request that one has not set in motion oneself. If an unsolicited message has led to a site asking for authentication, it is worth questioning why.
Essential actions to take at this point are:
– Put down any surprise verification or device-linking request
– Do not proceed with a login pop-up unless you initiated it
– Ask yourself why the site is calling for authentication
– Disregard any instructions to log in from an email or message you were not expecting
It is an uncomfortable truth but an important one: the fact that a Google or Microsoft page looks the part is no assurance of safety. As GTIG makes clear, the familiar is being turned into a trap by attackers, so one cannot afford to be less than vigilant at every click.











