Google Threat Intelligence Group (GTIG) has detailed several Russia-linked cyber espionage clusters targeting people in academia, think tanks, and other organizations in the United States and Europe.
The activity involves OAuth phishing, device-code phishing, spoofed websites, and infrastructure designed to imitate trusted organizations and cloud services.
The tracked clusters UNC6293, UNC7005, and UNC5976 show different levels of operational maturity. However, their campaigns rely on a common goal: convincing targets to grant attackers access to email, cloud accounts, or messaging platforms.
UNC6293 used the domains foreignrelations[.]us and dosportal[.]app in OAuth phishing campaigns. The first domain was registered and became active on November 21, 2025, after years without DNS activity.
Russia-Linked OAuth Phishing Campaigns
Historical registration data linked foreignrelations[.]us to two additional domains: internationalaffairsportal[.]us and stateaffairs[.]us.
All three were registered around the same period through Dynadot, suggesting possible infrastructure overlap. The registrant email used an address at 2200freefonts[.]com, although the font-related domain itself is not confirmed as actor-controlled.
The foreignrelations[.]us lure copied content associated with the Council on Foreign Relations. Analysts identified other sites sharing a Council on Foreign Relations Facebook App ID meta tag, a useful pivot for hunting cloned or proxied web content.
The tag alone does not prove malicious activity, but it can narrow investigation targets. Researchers also found structural links between dosportal[.]app subdomains and the-washington-ballet[.]com.
Shared CSS characteristics exposed two possible origin IP addresses behind Cloudflare-fronted infrastructure: 151.236.15[.]213 and 185.158.250[.]155.
Several stateaffairs[.]us and the-washington-ballet[.]com subdomains displayed behavior consistent with possible Evilginx phishing frameworks.
The sites redirected victims to legitimate U.S. Department of State and Washington Ballet pages, likely helping the operators make their phishing lures appear more credible.
UNC7005 has targeting overlap with UNC6293 but reportedly has weaker operational security and also uses malware. Its campaigns include Microsoft device-code phishing and phishing attempts against WhatsApp accounts.
The domain my-invite[.]org supported email-based phishing and briefly resolved to 104.194.159[.]150. Its lure changed from an Institute of Advanced Studies event to a fake GLOBSEC Forum 2026 invitation in Prague.
The page used registration[@]globsec[.]org, even though globsec[.]org is a legitimate and unrelated organization. Another domain, statistic-ms[.]live, redirected users to ad-g[.]org/login, which displayed an “Ad Manager” login page.
Domains including fllefolder[.]com, sharefolders[.]org, formshare[.]cloud, sharedfolders[.]org, usercontent[.]app, and fileshareapp[.]org showed similarities to the phishing infrastructure.
Some domains remain only suspected links, especially those identified through registration-based pivots, validin said. The research shows why defenders should track more than a single malicious domain.
Historical DNS records, registration timing, certificate data, favicon hashes, web-page headers, and copied content can reveal related infrastructure but each pivot requires validation before it is treated as confirmed malicious activity.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN
