Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-20 and was added to the RWP archive on 2026-09-07.
Three Russian clusters are phishing OAuth — ICE RELIC's door, not a new wiper
GTIG 20 August 2026 — UNC6293, UNC7005, UNC5976 hit academia, aero/defense, governments, think tanks in Europe and U.S. academia. App-password and OAuth-flow abuse. High-confidence Russian nexus; UNC6293 moderate as ICE RELIC (APT29) initial access.
Bottom line up front
CONFIRMED 20 August 2026 GTIG described three distinct suspected Russian espionage clusters — UNC6293, UNC7005, UNC5976 — abusing legitimate authentication flows (phishing, OAuth, and/or malware) against people, not plants. Victimology: academia, aerospace/defense, government, think tanks in Europe; academia and think tanks in the United States. High confidence on Russian nexus (targeting, themes, shared technique). UNC6293: moderate confidence as ICE RELIC (APT29) initial-access subcluster; June 2025 app-password phishing against Russia critics was the earlier public slice (Citizen Lab).
This is mailbox and SaaS identity. It is not Sandworm on a PLC.
What happened
Three clusters, not one blob. They ride sign-in flows Google already documented for UNC6293, then two more with overlapping taste in victims.
Why it matters
Think-tank and university Google/Microsoft accounts are how you read the same cables the ministry wants. Passkeys and app-password bans matter more here than a new EDR pack.
What is confirmed vs not
CONFIRMED GTIG three-cluster model and victim classes.
ASSESSED UNC6293 ⊂ ICE RELIC (moderate, GTIG).
UNKNOWN full malware chain on every cluster.
What defenders should do
- Kill legacy app passwords. Alert on new OAuth grants to unknown apps.
- High-risk individuals (Russia research, defense academia) get phishing-resistant MFA, not SMS.
- Do not merge this with UNC6671 vishing-for-extortion. Different money.
RWP assessment
Confidence: High that the campaign is identity-centric Russian collection. Low that it implies OT impact at those aerospace names.
Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-20 and was added to the RWP archive on 2026-09-07.
Sources
- GTIG — Distinct clusters target individuals of interest to Russia
- GTIG — ICE RELIC naming (APT29)
- Citizen Lab — UNC6293 app-password phishing (as cited by GTIG, June 2025)