UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
Campaign
Summary
Hide ▲
Show ▼
A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and European defense targets. The operation is actively stealing tokens and steering victims through legitimate login flows to make takeover attempts harder to spot. Between August 6 and August 13, 2026, the group sent targeted phishing emails to people in or related to the European defense industry. The activity spans Ukraine, Western Europe, and the U.S. and is designed for repeated account access rather than a single one-off lure.
Related Happenings
Microsoft 365 AitM phishing campaign using residential proxies
Campaign
H score34
First: 07.08.2026 13:38
Last: 07.08.2026 13:38
Sources 1
About this happening:
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft 365 AitM phishing campaign using residential proxies
CampaignAbout this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
Campaign
H score40
First: 01.08.2026 09:29
Last: 01.08.2026 09:29
Sources 1
How related:
These efforts also dovetail with a campaign called CaptiveCrunch, which was documented by ReliaQuest and Microsoft late last month.
About this happening:
CaptiveCrunch is a Midnight Blizzard / APT29 / Storm-2945 campaign that has used compromised captive Wi‑Fi portals to redirect users in hotels, conference centers, a...
CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
CampaignHow related: These efforts also dovetail with a campaign called CaptiveCrunch, which was documented by ReliaQuest and Microsoft late last month.
About this happening: CaptiveCrunch is a Midnight Blizzard / APT29 / Storm-2945 campaign that has used compromised captive Wi‑Fi portals to redirect users in hotels, conference centers, a...
Latest development: 20.08.2026 22:59
CaptiveCrunch targets captive Wi-Fi portals in hotels, conference centers, and airports in the U.S. and elsewhere by taking administrative access to Wi-Fi gateways, poisoning DNS, and redirecting users to attacker-controlled infrastructure; Microsoft said the traffic manipulation attacks have been ongoing since early May 2026.
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
Campaign
H score38
First: 24.07.2026 18:12
Last: 24.07.2026 18:12
Sources 1
About this happening:
BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
CampaignAbout this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
Kratos ecosystem shift changes threat-actor operations
Threat Actor Meta
H score39
First: 22.07.2026 02:07
Last: 22.07.2026 02:07
Sources 1
About this happening:
The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Kratos ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...
Latest development: 05.08.2026 14:43
Kali365 uses device-code phishing to target US organizations, presenting lures that impersonate SharePoint, OneDrive, or DocuSign before redirecting victims to Microsoft's legitimate device login portal for attacker-provided codes; successful approvals can yield access and refresh tokens with continued access to Microsoft 365 email, documents, and cloud resources, and ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week.
Timeline
-
20.08.2026 22:59 1 articles · 1h ago
UNC7005 registers Finnish Operations Center spoofing domains
Campaign Scope UpdateUNC7005 registers domains that spoof the legitimate Finnish Operations Center to support phishing against organizations in the defense and security markets, specifically in the context of NATO.
Show sources
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts — thehackernews.com — 20.08.2026 22:59
-
20.08.2026 22:59 1 articles · 1h ago
UNC7005 sends phishing emails to European defense targets
Exploitation ObservedUNC7005 sends targeted phishing emails to targets in or related to the European defense industry, using attacker-controlled domains to steer victims into Google OAuth credential theft.
Show sources
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts — thehackernews.com — 20.08.2026 22:59
-
20.08.2026 22:59 2 articles · 1h ago
Google details UNC7005's OAuth and WhatsApp account-hijack campaign
Technical Analysis UpdateGoogle Threat Intelligence Group details UNC7005's use of Google OAuth phishing, WhatsApp spoofing, and device-code phishing against academia, diplomatic, nonprofit, and defense personnel across Ukraine, Western Europe, and the U.S.
Show sources
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts — thehackernews.com — 20.08.2026 22:59
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts — thehackernews.com — 20.08.2026 22:59