Find notable cyber news and cases, enriched with sources, timelines, and signals.

UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign

Campaign
First reported
Last updated
Happening score
H score 16
1 unique sources, 1 articles

Summary

Hide ▲

A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and European defense targets. The operation is actively stealing tokens and steering victims through legitimate login flows to make takeover attempts harder to spot. Between August 6 and August 13, 2026, the group sent targeted phishing emails to people in or related to the European defense industry. The activity spans Ukraine, Western Europe, and the U.S. and is designed for repeated account access rather than a single one-off lure.

Related Happenings

SVG voicemail phishing campaign

Campaign
H score42 First: 28.08.2026 16:00 Last: 28.08.2026 16:00 Sources 1

About this happening: The SVG voicemail phishing campaign is a broad-spray operation that delivered 26,589 messages to 5,527 organizations, increasing the chance of email-defense bypass and...

Mirage2FA Microsoft 365 phishing-as-a-service campaign

Campaign
H score53 First: 25.08.2026 14:56 Last: 25.08.2026 14:56 Sources 1

About this happening: The Mirage2FA phishing-as-a-service campaign is actively targeting Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication, pu...

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
H score34 First: 07.08.2026 13:38 Last: 07.08.2026 13:38 Sources 1

About this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...

CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign

Campaign
H score40 First: 01.08.2026 09:29 Last: 01.08.2026 09:29 Sources 1

How related: These efforts also dovetail with a campaign called CaptiveCrunch, which was documented by ReliaQuest and Microsoft late last month.

About this happening: CaptiveCrunch is a Midnight Blizzard / APT29 / Storm-2945 campaign that has used compromised captive Wi‑Fi portals to redirect users in hotels, conference centers, a...

Latest development: 20.08.2026 22:59

CaptiveCrunch targets captive Wi-Fi portals in hotels, conference centers, and airports in the U.S. and elsewhere by taking administrative access to Wi-Fi gateways, poisoning DNS, and redirecting users to attacker-controlled infrastructure; Microsoft said the traffic manipulation attacks have been ongoing since early May 2026.

BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign

Campaign
H score38 First: 24.07.2026 18:12 Last: 24.07.2026 18:12 Sources 1

About this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...

Timeline

  1. 20.08.2026 22:59 2 articles · 13d ago

    Google details UNC7005's OAuth and WhatsApp account-hijack campaign

    Technical Analysis Update

    Google Threat Intelligence Group details UNC7005's use of Google OAuth phishing, WhatsApp spoofing, and device-code phishing against academia, diplomatic, nonprofit, and defense personnel across Ukraine, Western Europe, and the U.S.

    Show sources