Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Summary

Three suspected Russian cyber espionage groups are targeting individuals in academia, aerospace, defense, and government sectors in Europe and the U.S. These groups are exploiting legitimate authentication methods like Google OAuth and WhatsApp linking to hijack accounts.

IFF Assessment

FOE

The identified threat actors are actively compromising accounts and engaging in espionage, posing a direct threat to targeted organizations and individuals.

Defender Context

Defenders should be aware of these evolving tactics used by Russian threat actors to compromise accounts through legitimate authentication flows. Implementing robust multi-factor authentication and monitoring for suspicious login activity related to Google OAuth and WhatsApp linking can help mitigate these risks.

Read Full Story →