Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Government, defense, and academic institutions
Incident: Targeted OAuth and account hijacking campaigns conducted by Russian threat clusters.
Impact: Complete account takeover leading to stealthy data exfiltration and internal phishing operations.
Attacker: Russian-linked clusters (including APT29/Ice Relic)
Analysis: Three Russian-linked threat clusters are employing sophisticated social engineering to trick targets into surrendering OAuth tokens and verification codes. By abusing legitimate Google Cloud infrastructure and fake file-sharing lures, these actors can bypass standard login protections to gain persistent account access. This strategy facilitates rapid data exfiltration and allows attackers to launch further phishing attacks from trusted accounts.
Recommendations: Implement FIDO2-compliant hardware security keys to mitigate token-based phishing.; Conduct regular audits of third-party OAuth permissions and application-specific passwords.; Train high-risk personnel to never share verification codes or full URLs with external parties.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source