State-Sponsored Phishing Targets European Officials via Messaging Apps and OAuth Exploits
August 25, 2026
European officials are being targeted by state-sponsored spearphishing campaigns that use social engineering and links to hijack senior officials’ messaging accounts, including via WhatsApp.
These attacks rely on highly personalized messages that prompt recipients to click suspicious links and grant access to compromised accounts.
Google Threat Intelligence and other researchers note three Russian-linked clusters—UNC6293, UNC7005, and UNC5976—exploiting legitimate authentication flows (OAuth, app passwords, device linking) to harvest tokens and access across Google, Microsoft Entra ID, and messaging apps.
Google recommends practical defenses: avoid setting app passwords for unsolicited requests, revoke unfamiliar app passwords, review linked devices, treat unsolicited OAuth prompts with suspicion, and consider the Advanced Protection Program for high-risk individuals.
UNC5976 operates with automated token collection via cloud infrastructure and has created multiple attacker-controlled domains since early 2026, focusing on Ukraine, Armenia, and related defense/NGO sectors.
From August 2026, all three groups adopted cloud-based OAuth phishing, with UNC6293 and UNC5976 showing post-compromise infrastructure and heavier malware usage, while UNC7005 uses app-password and device-link phishing.
Experts warn these campaigns pose broader supply-chain risk by potentially compromising MSPs and leveraging trusted networks for wider access.
DeepSeek, favored by attackers for its power and relatively loose guardrails, enables cheaper, scalable operations than tightly controlled defense models.
Defenses include threat intelligence and tools like Bitdefender Scamio and Bitdefender Ultimate Security to analyze suspicious messages, links, QR codes, and provide broader anti-phishing protection.
EU institutions emphasize protecting sensitive information with internal encryption and secure tools, but face challenges such as divergent digital signatures, lack of a common collaboration platform, and inconsistent document classification.
The campaigns increasingly abuse normal authentication flows (OAuth, app passwords, device linking) to harvest tokens, making phishing harder to detect and enabling cross-platform account compromise.
In addition to Google and Microsoft ecosystems, attackers exploit everyday workflows and trusted contacts, using familiar lures such as diplomatic events and conferences to harvest credentials.
Summary based on 12 sources
Get a daily email with more Tech stories
Sources

DEV Community • Aug 22, 2026
Three Russian-Linked Clusters Abuse Legitimate Authentication Flows
TNW | Data-security • Aug 26, 2026
EU officials were targeted on WhatsApp, an internal document shows
The Hacker News • Aug 20, 2026
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Security Affairs • Aug 21, 2026
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics