Today, WhatsApp and Google Login play a major role in digital activities. People use them for account access, file sharing, and connecting services. However, cyber criminals are now exploiting these trusted systems and authentication methods. Recently, the Google Threat Intelligence Group (GTIG) highlighted activities linked to three suspected Russian cyber espionage groups. These groups include UNC6293, UNC7005, and UNC5976.
According to GTIG, these groups targeted people connected with academic institutions, aerospace sectors, defence organisations, government bodies, and think tanks in Europe and America.
Cyber criminals misuse Google Login authentication
Cyber attackers do not always rely on fake login pages to trap users. Instead, groups like UNC5976 use OAuth phishing methods to target accounts. Through this method, attackers redirect users to genuine Google Login pages. After users complete normal login steps, attackers try gaining authentication tokens through controlled cloud projects.
These tokens can help attackers attempt access to user accounts. Similarly, UNC7005 used fake domains and cloud infrastructure to redirect users towards genuine Google OAuth Login pages.
After login completion, the group attempted to steal authentication tokens for further access.
WhatsApp device linking creates another risk
Cyber criminals are also misusing WhatsApp’s Device Linking feature. Attackers often create situations involving secure calls, chats, or document sharing. After gaining trust, they ask users for phone numbers and request device connections through QR codes or linking codes.
If users accidentally link an attacker-controlled device with their WhatsApp account, attackers may try reading chats, sending messages, and accessing private information.
In some cases, attackers displayed fake pages offering voice calls, encrypted chats, or file downloads.
Steps to protect WhatsApp and Google accounts
Users should activate Two-Step Verification on WhatsApp for stronger account protection. This feature adds an extra PIN layer for account security.
Additionally, users can use WhatsApp Passkeys connected with fingerprints, Face Unlock, or screen locks. Moreover, users should avoid accepting unknown device linking requests. They should never share WhatsApp verification codes with anyone. Users should also use features like unknown call silencing, Privacy Check-Up, and blocking or reporting suspicious messages.
Furthermore, users must avoid logging into Google accounts through unknown links or suspicious websites.
Even if a page appears similar to Google Login, users should verify its authenticity before entering details.
OAuth phishing attacks can redirect users to genuine Google Login pages while attempting to steal authentication tokens later. Therefore, users must carefully check login requests from unknown domains and avoid suspicious links.












