2026-08-23HIGHNo exploit and no payload, the victim approves the attacker's session, or issues a credential the second factor never sees
UNC5976
actor · actor:unc5976 single-source
Suspected Russia-nexus espionage cluster tracked by Google Threat Intelligence Group since March 2026 and assessed as operationally distinct from the ICE RELIC-linked clusters. Buys file-sharing-themed domains, stands up a cloud project per domain, and harvests OAuth tokens after routing targets through a genuine consent flow; also distributed the HEADRUSH malicious spreadsheet plugin (Google Threat Intelligence Group, 2026-08-20).
Coverage
1
first 2026-08-23 → last 2026-08-23
Latest activity
2026-08-23
No exploit and no payload, the victim approves the attacker's session, or issues a credential the second…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, defense, education · regions: europe, us
Sources cited
1
1 hosts
Action items (2)
Do-now tasks recorded on the entries about UNC5976, newest first. Check the date before acting on an older one.
- Disable application-specific passwords tenant-wide if your identity platform still permits them; they are the one credential class in this research that defeats multi-factor authentication outright, and for most organisations nothing legitimate still depends on them.2026-08-23No exploit and no payload, the victim approves the…
- Restrict the OAuth device-code authorisation flow by policy to the users and locations that genuinely need it, and alert on device-code grants completed from a different network than the sign-in that requested them.2026-08-23No exploit and no payload, the victim approves the…
Defender insights
What each entry about UNC5976 tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
uses
- HEADRUSHmalicious Excel plugin leading to a scripted downloader, delivered via a domain impersonating a Ukrainian research institute
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (7 across 7 tactics)
7 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessPhishing: Spearphishing Link
- ExecutionUser Execution: Malicious File
- PersistenceModify Authentication Process: Multi-Factor Authentication
- StealthSystem Binary Proxy Execution: Mshta
- Defense ImpairmentModify Authentication Process: Multi-Factor Authentication
- Credential AccessSteal Application Access Token · Modify Authentication Process: Multi-Factor Authentication
- CollectionAudio Capture · Video Capture
Initial Access TA0001
T1566.002Phishing: Spearphishing Link×1
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗
Execution TA0002
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗
Persistence TA0003
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗
Stealth TA0005
T1218.005System Binary Proxy Execution: Mshta×1
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code
Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗
Defense Impairment TA0112
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗
Credential Access TA0006
T1528Steal Application Access Token×1
Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗
Collection TA0009
T1123Audio Capture×1
An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listening into sensitive conversations to gather information.
Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗
T1125Video Capture×1
An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering information. Images may also be captured from devices or applications, potentially in specified intervals, in lieu of video files.
Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗
Entries about UNC5976 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- CaptiveCrunch×1
- Google Workspace×1
- HEADRUSH×1
- Microsoft Entra ID×1
- Midnight Blizzard×1
- Storm-2945×1
- UNC6293×1
- WhatsApp×1
Where this entity is cited
Source distribution
- cloud.google.com1 (100%)