Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

August 20, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Government, defense, and academic institutions
Incident: Targeted OAuth and account hijacking campaigns conducted by Russian threat clusters.
Impact: Complete account takeover leading to stealthy data exfiltration and internal phishing operations.
Attacker: Russian-linked clusters (including APT29/Ice Relic)
Analysis: Three Russian-linked threat clusters are employing sophisticated social engineering to trick targets into surrendering OAuth tokens and verification codes. By abusing legitimate Google Cloud infrastructure and fake file-sharing lures, these actors can bypass standard login protections to gain persistent account access. This strategy facilitates rapid data exfiltration and allows attackers to launch further phishing attacks from trusted accounts.
Recommendations: Implement FIDO2-compliant hardware security keys to mitigate token-based phishing.; Conduct regular audits of third-party OAuth permissions and application-specific passwords.; Train high-risk personnel to never share verification codes or full URLs with external parties.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *