Tag
high
threat
Russian Threat Clusters UNC6293, UNC7005, and UNC5976 Targeted OAuth and Device Code Phishing Campaigns
3 TTPsThree suspected Russian threat clusters are actively conducting targeted phishing campaigns using OAuth abuse, device code manipulation, and AitM attacks via compromised Wi-Fi gateways to hijack credentials and deploy infostealers.
Google Cloud +2
UNC7005
phishing
espionage
oauth-abuse
aitm
credential-theft
3t
high
threat
ShinyHunters OAuth Abuse Targeting SaaS Applications
6 TTPsShinyHunters, and related threat actor Storm-3138, conducted campaigns between mid-2025 and mid-2026 by employing voice phishing, supply chain compromise, and misconfigured guest access to abuse trusted OAuth relationships in SaaS applications like Salesforce, leading to unauthorized access, data exfiltration, and persistence.
Salesforce +4
ShinyHunters
oauth-abuse
saas
supply-chain
vishing
data-exfiltration
persistence
cloud
6t