UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
Campaign
Summary
Hide ▲
Show ▼
A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and European defense targets. The operation is actively stealing tokens and steering victims through legitimate login flows to make takeover attempts harder to spot. Between August 6 and August 13, 2026, the group sent targeted phishing emails to people in or related to the European defense industry. The activity spans Ukraine, Western Europe, and the U.S. and is designed for repeated account access rather than a single one-off lure.
Related Happenings
SVG voicemail phishing campaign
Campaign
H score42
First: 28.08.2026 16:00
Last: 28.08.2026 16:00
Sources 1
About this happening:
The SVG voicemail phishing campaign is a broad-spray operation that delivered 26,589 messages to 5,527 organizations, increasing the chance of email-defense bypass and...
SVG voicemail phishing campaign
CampaignAbout this happening: The SVG voicemail phishing campaign is a broad-spray operation that delivered 26,589 messages to 5,527 organizations, increasing the chance of email-defense bypass and...
Mirage2FA Microsoft 365 phishing-as-a-service campaign
Campaign
H score53
First: 25.08.2026 14:56
Last: 25.08.2026 14:56
Sources 1
About this happening:
The Mirage2FA phishing-as-a-service campaign is actively targeting Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication, pu...
Mirage2FA Microsoft 365 phishing-as-a-service campaign
CampaignAbout this happening: The Mirage2FA phishing-as-a-service campaign is actively targeting Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication, pu...
Microsoft 365 AitM phishing campaign using residential proxies
Campaign
H score34
First: 07.08.2026 13:38
Last: 07.08.2026 13:38
Sources 1
About this happening:
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft 365 AitM phishing campaign using residential proxies
CampaignAbout this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
Campaign
H score40
First: 01.08.2026 09:29
Last: 01.08.2026 09:29
Sources 1
How related:
These efforts also dovetail with a campaign called CaptiveCrunch, which was documented by ReliaQuest and Microsoft late last month.
About this happening:
CaptiveCrunch is a Midnight Blizzard / APT29 / Storm-2945 campaign that has used compromised captive Wi‑Fi portals to redirect users in hotels, conference centers, a...
CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
CampaignHow related: These efforts also dovetail with a campaign called CaptiveCrunch, which was documented by ReliaQuest and Microsoft late last month.
About this happening: CaptiveCrunch is a Midnight Blizzard / APT29 / Storm-2945 campaign that has used compromised captive Wi‑Fi portals to redirect users in hotels, conference centers, a...
Latest development: 20.08.2026 22:59
CaptiveCrunch targets captive Wi-Fi portals in hotels, conference centers, and airports in the U.S. and elsewhere by taking administrative access to Wi-Fi gateways, poisoning DNS, and redirecting users to attacker-controlled infrastructure; Microsoft said the traffic manipulation attacks have been ongoing since early May 2026.
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
Campaign
H score38
First: 24.07.2026 18:12
Last: 24.07.2026 18:12
Sources 1
About this happening:
BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
CampaignAbout this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
Timeline
-
20.08.2026 22:59 1 articles · 13d ago
UNC7005 registers Finnish Operations Center spoofing domains
Campaign Scope UpdateUNC7005 registers domains that spoof the legitimate Finnish Operations Center to support phishing against organizations in the defense and security markets, specifically in the context of NATO.
Show sources
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts — thehackernews.com — 20.08.2026 22:59
-
20.08.2026 22:59 1 articles · 13d ago
UNC7005 sends phishing emails to European defense targets
Exploitation ObservedUNC7005 sends targeted phishing emails to targets in or related to the European defense industry, using attacker-controlled domains to steer victims into Google OAuth credential theft.
Show sources
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts — thehackernews.com — 20.08.2026 22:59
-
20.08.2026 22:59 2 articles · 13d ago
Google details UNC7005's OAuth and WhatsApp account-hijack campaign
Technical Analysis UpdateGoogle Threat Intelligence Group details UNC7005's use of Google OAuth phishing, WhatsApp spoofing, and device-code phishing against academia, diplomatic, nonprofit, and defense personnel across Ukraine, Western Europe, and the U.S.
Show sources
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts — thehackernews.com — 20.08.2026 22:59
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts — thehackernews.com — 20.08.2026 22:59