{"id":77173,"date":"2026-08-21T02:37:09","date_gmt":"2026-08-21T06:37:09","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=77173"},"modified":"2026-08-21T02:37:09","modified_gmt":"2026-08-21T06:37:09","slug":"russian-hackers-whatsapp-linking-attack-77173","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/russian-hackers-whatsapp-linking-attack-77173\/","title":{"rendered":"Russian hackers abuse WhatsApp linking to spy on high-value targets"},"content":{"rendered":"<p>Three suspected Russian cyber-espionage clusters are exploiting legitimate authentication features in <a href=\"https:\/\/www.whatsapp.com\/security\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">WhatsApp<\/a>, <a href=\"https:\/\/blog.google\/threat-analysis-group\/russian-espionage-campaigns-unc7005-whatsapp\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Google<\/a>, and Microsoft to compromise high-value targets, including academics, diplomats, defense personnel, and government-linked individuals. One group, tracked as UNC7005, has perfected a particularly insidious technique: tricking victims into linking their WhatsApp accounts to attacker-controlled devices, then recording audio and video through fake calls. This campaign, which Google assesses with high confidence as Russian-led, represents a significant escalation in espionage tradecraft because it abuses genuine authentication mechanisms rather than relying on traditional phishing pages.<\/p>\n<h2>Three Russian-Linked Clusters Target High-Value Individuals with Authentication Abuse<\/h2>\n<p>Google tracks the activity as UNC6293, UNC7005, and UNC5976, with all three clusters assessed as having a Russian nexus. UNC6293 and UNC7005 are further linked with moderate confidence to initial-access operations associated with ICE RELIC, Google&#8217;s name for the threat actor also known as APT29. The campaigns are particularly difficult to detect because they frequently abuse genuine authentication flows\u2014device-linking QR codes, OAuth tokens, and app passwords\u2014rather than deploying conventional fake login pages.<\/p>\n<h3>UNC7005: The WhatsApp Device-Linking Attack Chain<\/h3>\n<p>UNC7005, also tracked as STORM-2945, began targeting academics, diplomats, nonprofits, and researchers in Ukraine, Western Europe, and the United States in early 2026. During May and June, the group created phishing pages impersonating WhatsApp and invited targets to join supposedly secure calls, chats, or document-sharing sessions. The attack chain is deceptively simple yet highly effective.<\/p>\n<p>Victims are first asked for their phone number. The attackers then initiate a legitimate WhatsApp device-linking request and display its genuine QR code or linking code on the phishing page. Anyone following the instructions effectively authorizes an attacker-controlled device to access their WhatsApp account. This is not a fake page trick\u2014it is a real WhatsApp authentication flow, making it nearly indistinguishable from a normal linking process.<\/p>\n<h4>How Do Russian Hackers Abuse WhatsApp Device Linking?<\/h4>\n<p>The attackers initiate a legitimate WhatsApp device-linking request and display the genuine QR code or linking code on their phishing page. When the victim scans the code or enters the code, they authorize an attacker-controlled device to access their WhatsApp account. This gives the attackers full read and write access to messages, contacts, and media without the victim realizing their account has been compromised.<\/p>\n<p>After the linking succeeds, UNC7005 presents additional traps. Selecting a supposed voice call causes JavaScript to request camera and microphone access, record the victim during a fake ringing sequence, and upload the resulting WebM recording to an attacker-controlled command-and-control endpoint. Other options on the phishing page direct victims to a fake encrypted-chat login or offer a file download whose payload Google&#8217;s Threat Intelligence Group could not determine.<\/p>\n<h3>Beyond WhatsApp: Device-Code Phishing and Malware Deployment<\/h3>\n<p>UNC7005 has used several other infection methods. Microsoft device-code phishing pages impersonated diplomatic events such as GLOBSEC and fingerprinted visitors to detect automated analysis. The group also deployed VIDAR on Windows and AtomicStealer on macOS through a fake \u201cSummit Companion App,\u201d targeting browser credentials, cookies, payment details, and other stored information.<\/p>\n<p>Google additionally linked UNC7005 infrastructure to compromised hotel and conference-center captive portals reported by ReliaQuest and Microsoft. Those redirects led users to Microsoft-themed phishing infrastructure capable of device-code theft or malware delivery. Google also identified ENGINELIGHT malware and overlaps with the CHERRYPIE\/ChocoShell PowerShell infostealer, whose code contained artifacts suggesting LLM-assisted generation.<\/p>\n<h3>UNC6293 and UNC5976: OAuth and App-Password Theft<\/h3>\n<p>The other two clusters employ related authentication attacks. UNC6293 has impersonated the US State Department to convince targets to create app passwords or surrender OAuth verification codes. This technique leverages the trust users place in official government branding and the legitimate process of generating app-specific passwords for services that do not support modern authentication.<\/p>\n<p>UNC5976 has built fake file-sharing sites that redirect victims through legitimate Google OAuth pages before stealing authentication tokens. This cluster also deployed a malicious Excel plugin dubbed HEADRUSH, which led to an HTA downloader. The use of legitimate OAuth flows makes these attacks exceptionally hard to detect because the victim is actually approving a real authorization request, albeit to a malicious application.<\/p>\n<h2>The Strategic Significance of Abusing Legitimate Authentication<\/h2>\n<p>These campaigns represent a fundamental shift in cyber-espionage tactics. Rather than investing in zero-day exploits or complex malware, the <a href=\"https:\/\/overcentral.com\/en\/sharepoint-authentication-bypass-cve-2026-55040\/\" title=\"Attackers Exploit SharePoint Authentication Bypass After Public PoC Release\" data-iacss-internal=\"1\">attackers exploit<\/a> the very features designed to make authentication convenient. WhatsApp device linking, Microsoft device codes, and Google OAuth were built to streamline user experience\u2014but in the hands of threat actors, they become powerful espionage tools.<\/p>\n<p>The targeting profile is also telling. Academics, diplomats, defense personnel, and researchers in Ukraine, Western Europe, and the United States align directly with Russian intelligence priorities. The use of fake diplomatic events like GLOBSEC suggests sophisticated operational security and deep understanding <a href=\"https:\/\/overcentral.com\/en\/servant-of-the-lake-achievement-guide\/\" title=\"Servant Of The Lake Unlocks Every Achievement\" data-iacss-internal=\"1\">of the<\/a> target community&#8217;s behavior.<\/p>\n<p>Google&#8217;s high-confidence assessment of a Russian nexus, coupled with the moderate-confidence link to APT29, places these operations within the broader context of Russian state-sponsored cyber activities. APT29, also known as Cozy Bear, has historically targeted government networks, think tanks, and research institutions. The abuse of WhatsApp linking represents a tactical evolution that lowers the technical barrier for initial access while increasing stealth.<\/p>\n<h2>Practical Defense: How Users and Organizations Can Protect Against Linking Abuse<\/h2>\n<p>The most effective defense begins with user awareness. Anyone receiving an unexpected request to link a messaging device, enter a device code, create an app password, or approve an OAuth access should treat it with extreme suspicion. These are not normal authentication flows for initiating a call or sharing a document.<\/p>\n<p>WhatsApp users should regularly review linked devices in their account settings and immediately remove any that are unrecognized. Enabling two-step verification and registration protections adds a critical layer of security. For sensitive communications, verifying any invitation through a separate trusted channel\u2014such as a phone call or in-person conversation\u2014can prevent compromise.<\/p>\n<p>Organizations should implement policies that limit the use of personal messaging apps for work-related communications, especially among high-value personnel. Security teams should monitor for anomalous device-linking events, OAuth consent grants to unfamiliar applications, and unusual patterns in authentication logs.<\/p>\n<p>The broader implication is clear: as authentication mechanisms become more seamless and user-friendly, they also become more attractive targets. The Russian clusters tracked by Google have demonstrated that abusing legitimate features is not only effective but also harder to detect than traditional phishing. Security awareness training must evolve to address these specific attack vectors, emphasizing that not all authentic-looking authentication requests are safe.<\/p>\n<p>For those interested in staying informed on the latest cyber-espionage tactics, follow us on X\/Twitter and LinkedIn for exclusive content.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Three suspected Russian cyber-espionage clusters are exploiting legitimate authentication features in WhatsApp, Google, and Microsoft to compromise high-value targets, including academics, diplomats, defense personnel, and government-linked individuals. One group, tracked as UNC7005, has perfected a particularly insidious technique: tricking victims into linking their WhatsApp accounts to attacker-controlled devices, then recording audio and video through fake [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":82755,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/77173.png","fifu_image_alt":"Russian hackers abuse WhatsApp linking to spy on high-value targets","footnotes":""},"categories":[40668],"tags":[],"class_list":["post-77173","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/77173.png","fifu_image_alt":"Russian hackers abuse WhatsApp linking to spy on high-value targets","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/77173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=77173"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/77173\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/82755"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=77173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=77173"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=77173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}