Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Summary
Three suspected Russian cyber espionage groups are targeting individuals in academia, aerospace, defense, and government sectors in Europe and the U.S. These groups are exploiting legitimate authentication methods like Google OAuth and WhatsApp linking to hijack accounts.
IFF Assessment
FOE
The identified threat actors are actively compromising accounts and engaging in espionage, posing a direct threat to targeted organizations and individuals.
Defender Context
Defenders should be aware of these evolving tactics used by Russian threat actors to compromise accounts through legitimate authentication flows. Implementing robust multi-factor authentication and monitoring for suspicious login activity related to Google OAuth and WhatsApp linking can help mitigate these risks.