Russian Hackers Use Fake Google Drive and Diplomatic Lures to Steal Online Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Russian-linked operators are using fake cloud-storage pages and diplomatic themes to trick targets into giving away access to online accounts. The following article body is 650 words, excluding the IoC table.

Russian cyber espionage campaigns are using convincing Google Drive pages and diplomatic invitations to take over online accounts.

Instead of relying on a malicious download, the operators steer targets into legitimate sign-in processes and capture the access they need.

The activity has focused on people in academia, think tanks, government-linked bodies, and defense-related organizations in Europe and the United States.

Emails and webpages imitate familiar services, events, or institutions, making a request to view a document or register for a meeting appear routine.

Analysts at Validin identified further infrastructure around the campaigns after examining historical DNS records, website responses, certificates, registration data, and visual page features.

Validin said in a report shared with Cyber Security News (CSN) that their work expands on reporting by Google Threat Intelligence Group, which tracked the activity under the clusters UNC6293, UNC7005, and UNC5976. The impact can be serious even when a victim never installs traditional malware.

WhatsApp device code phishing lure (Source - Validin)
WhatsApp device code phishing lure (Source – Validin)

A stolen consent token, device code, app password, or active browser session can give an intruder access to email, cloud files, contacts, and trusted conversations, during routine work and potentially exposing sensitive diplomatic correspondence and external partners.

Russian Hackers Use Fake Google Drive

The UNC5976 cluster used a Google Drive lookalike domain in an OAuth phishing operation. Validin captured the page with the title “My Drive – Google Drive,” a small detail designed to reassure a recipient who expected to open or share a file.

OAuth phishing abuses a real authorization process rather than simply asking for a password on a crude fake form. A target can be sent to a genuine provider sign-in page, then prompted to approve an attacker-controlled application.

That approval may hand over tokens that let attackers reach account data without needing the password again. The researchers found similar hosting and content patterns across additional lookalike domains, showing how quickly an operation can rotate its web infrastructure.

This approach aligns with earlier reporting on Russian hackers abuse OAuth, where tailored themes were used to push targets toward account takeovers.

Fake login prompt (Source - Validin)
Fake login prompt (Source – Validin)

Validin also recorded a distinctive fake Drive favicon and matching page characteristics that helped narrow a much larger set of possible sites.

Such technical traces matter because names alone are unreliable: attackers can register and abandon domains rapidly, while copied page templates and server behavior can expose a broader campaign.

Diplomatic Lures Broaden the Campaign

UNC6293 used foreign policy-themed web lures to support OAuth phishing. The material copied content connected to the Council on Foreign Relations, while related names referenced international affairs and state matters, giving the operation a credible policy-focused appearance.

The campaign also showed signs of proxy-based phishing. Several campaign-linked subdomains briefly redirected visitors to legitimate U.S. State Department and Washington Ballet pages.

Validin assessed the responses as possible Evilginx configurations, a technique associated with live interception of sign-in sessions.

A separate cluster, UNC7005, used fake invitations to target Microsoft and WhatsApp accounts through device-code phishing. One lure promoted a supposed Prague event and changed its branding and deadline over time.

A domain hosted on pages[.]dev (Source - Validin)
A domain hosted on pages[.]dev (Source – Validin)

The tactic reflects the growing use of familiar account-linking screens, also seen in Russian hackers spoof European events, to make urgent authentication requests feel legitimate.

Combining historical DNS, page captures, certificate data, and registration records can uncover related infrastructure.

The researchers caution that pivots need verification, since shared hosting, expired DNS, and copied web content can create misleading overlaps.

Organizations should treat unexpected Drive shares, conference invitations, and device-linking requests as potential account-theft attempts, particularly when they arrive from an unfamiliar domain.

Users should independently open the service instead of following the message link, review an OAuth application’s requested permissions, and report suspicious pages.

Security teams should monitor unusual consent grants and session activity, while phishing-resistant sign-in methods can reduce exposure to proxy-style attacks described in Evilginx AiTM phishing attacks.

The technical indicators associated with this activity, including newly identified related infrastructure, appear in the table below for defensive monitoring and blocking.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain foreignrelations[.]us UNC6293 OAuth phishing lure
Domain dosportal[.]app UNC6293 OAuth phishing lure
Domain internationalaffairsportal[.]us Suspected UNC6293-related domain
Domain stateaffairs[.]us Suspected UNC6293-related domain; possible proxy-phishing activity
Domain the-washington-ballet[.]com Suspected UNC6293-related domain; possible proxy-phishing activity
IP address 151.236.15[.]213 Possible origin IP for UNC6293-related infrastructure
IP address 185.158.250[.]155 Possible origin IP for UNC6293-related infrastructure
Email address given956[@]2200freefonts[.]com Registrant email associated with suspected UNC6293 domains
Domain 2200freefonts[.]com Domain used in the registrant email; not attributed to UNC6293
Domain my-invite[.]org UNC7005 phishing infrastructure
IP address 104.194.159[.]150 Historical resolution for my-invite[.]org
Domain ms365-live[.]com Related infrastructure overlap
Domain statistic-ms[.]live UNC7005 redirect infrastructure
URL https[:]//ad-g[.]org/login Login page reached through statistic-ms[.]live
Domain ad-g[.]org UNC7005-related phishing infrastructure
Domain drive[.]google[.]verify-drive[.]com UNC5976 OAuth phishing lure
Domain verify-drive[.]com Related UNC5976 infrastructure
IP address 93.127.160[.]28 Historical hosting IP for verify-drive[.]com
Domain fllefolder[.]com Suspected UNC5976-related domain
Domain sharefolders[.]org Suspected UNC5976-related domain
Domain drive[.]google[.]sharefolders[.]org Suspected UNC5976-related domain
Domain formshare[.]cloud Suspected UNC5976-related domain
Domain drive[.]google[.]formshare[.]cloud Suspected UNC5976-related domain
Domain sharedfolders[.]org Suspected UNC5976-related domain
Domain drive[.]google[.]sharedfolders[.]org Suspected UNC5976-related domain
Domain eurcpa[.]org Suspected UNC5976-related domain
Domain drive[.]google[.]anticorruption[.]eurcpa[.]org Suspected UNC5976-related domain
Domain sharedfolders[.]app Suspected UNC5976-related domain
Domain drive[.]google[.]sharedfolders[.]app Suspected UNC5976-related domain
Domain usercontent[.]app Suspected UNC5976-related domain
Domain drive[.]google[.]usercontent[.]app Suspected UNC5976-related domain
Domain usercontent[.]online Suspected UNC5976-related domain
Domain drive[.]google[.]usercontent[.]online Suspected UNC5976-related domain
Domain fileshareapp[.]org Net-new domain with similar content and a valid certificate
Domain linkfileshare[.]net Registration-pivot discovery
Domain drive[.]google[.]linkfileshare[.]net Registration-pivot discovery
Domain supportnoreplay[.]com Low-confidence registration pivot
Domain security-forms[.]com Low-confidence registration pivot
Domain noreplaysupport[.]com Low-confidence registration pivot
Domain info-forms[.]com Low-confidence registration pivot
CSS hash 6971626bf83b92c4ceef538c8919ca17 Shared CSS class hash associated with lookalike infrastructure
HTTP header hash e4c0a20a5e50632867cd Header hash used to identify similar fake Drive pages
Favicon MD5 c66f20f2e39eb2f6a0a4cdbe0d955e5f Distinctive fake Google Drive favicon hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Russian Hackers Use Fake Google Drive and Diplomatic Lures to Steal Online Account appeared first on Cyber Security News.