{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/ice-relic/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["ICE RELIC"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Microsoft Account","WhatsApp"],"_cs_severities":["high"],"_cs_tags":["phishing","credential-theft","oauth","espionage","ice-relic"],"_cs_type":"threat","_cs_vendors":["Microsoft","Meta"],"content_html":"\u003cp\u003eGoogle Threat Intelligence Group (GTIG) has identified two distinct threat clusters, UNC6293 and UNC7005, actively targeting individuals in academia, aerospace, defense, and government sectors across Europe and the United States. These clusters, assessed as operating under the broader ICE RELIC (formerly APT29) umbrella, leverage sophisticated social engineering to manipulate legitimate authentication workflows. By impersonating government officials or conference organizers, the attackers trick targets into generating app-specific passwords, performing OAuth consent grants, or providing device activation codes. These techniques effectively circumvent multi-factor authentication (MFA) by tricking the user into granting the attacker authorized access to their accounts. While UNC6293 demonstrates a more refined operational security and focus on diplomatic themes, UNC7005 has been observed using similar tactics alongside malware delivery. These operations are typically small-scale and highly targeted, focusing on high-value individuals critical of Russian state policy.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker conducts reconnaissance to identify individuals of interest within academia, defense, or government sectors.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a lure, such as a PDF or email, impersonating a reputable entity (e.g., U.S. State Department, GLOBSEC).\u003c/li\u003e\n\u003cli\u003eThe attacker hosts a spoofed landing page (e.g., at foreignrelations[.]us) designed to facilitate a specific authentication flow.\u003c/li\u003e\n\u003cli\u003eThe victim is directed to the malicious site through spearphishing, where they are prompted to initiate an authentication process.\u003c/li\u003e\n\u003cli\u003eThe victim is coerced into performing a specific action: creating an app password, performing an OAuth token request, or generating a device code.\u003c/li\u003e\n\u003cli\u003eThe victim provides the resulting sensitive credential (app password, code, or OAuth URL) to the attacker via a web form or email.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the obtained credential to authenticate to the target's account, bypassing MFA requirements.\u003c/li\u003e\n\u003cli\u003eThe attacker gains unauthorized access to the victim's data, such as emails, contacts, or documents, for espionage purposes.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful compromise of these accounts allows for the exfiltration of sensitive diplomatic, academic, and defense-related intelligence. By bypassing MFA, the attackers gain long-term, stealthy access to personal and institutional communication channels. These campaigns have been observed targeting prominent critics of the Russian state, with the potential to influence policy and disrupt organizational operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement Conditional Access policies to restrict or block the creation and use of legacy app-specific passwords where possible.\u003c/li\u003e\n\u003cli\u003eAudit and restrict the ability of users to grant OAuth permissions to unverified third-party applications.\u003c/li\u003e\n\u003cli\u003eTrain staff on the risks of device code phishing, emphasizing that they should never share authorization codes with anyone.\u003c/li\u003e\n\u003cli\u003eBlock traffic to the known malicious domain foreignrelations[.]us at the organization's network perimeter.\u003c/li\u003e\n\u003cli\u003eDeploy identity-focused monitoring to detect anomalous sign-ins occurring immediately after a user has performed an authentication action on an external site.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T19:09:58Z","date_published":"2026-08-20T19:09:58Z","id":"https://feed.craftedsignal.io/briefs/2026-08-russian-auth-flow-abuse/","summary":"Suspected Russian threat clusters UNC6293 and UNC7005 are abusing legitimate OAuth, app password, and device code authentication workflows to bypass MFA and compromise high-value targets in academia, government, and defense.","title":"Russian-Linked Clusters Abuse Authentication Flows for Targeted Credential Theft","url":"https://feed.craftedsignal.io/briefs/2026-08-russian-auth-flow-abuse/"}],"language":"en","title":"CraftedSignal Threat Feed - ICE RELIC","version":"https://jsonfeed.org/version/1.1"}