Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff.
Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead.
Threat actors target researchers, academics, government officials, think-tank analysts, and defense sector personnel across Europe and the United States. The three clusters are tracked as UNC6293, UNC7005, and UNC5976, and while they operate differently and with different tools, Google published them together for a reason.
“These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms.” reads the report published by GTIG. “Because these operations abuse legitimate authentication flows which may not immediately seem like phishing attempts to users, GTIG is raising awareness about these social engineering campaigns targeting individuals so that targets can more readily recognize malicious outreach.”
UNC6293 is the oldest of the three and the most precisely attributed. Google assesses with moderate confidence that it’s a sub-cluster of ICE RELIC, the group also tracked as APT29, responsible for initial access operations.
Its operations are narrow by design: typically fewer than five targets at a time, with themes built around diplomatic events and upcoming conferences. Since it was first documented in June 2025, UNC6293 has consistently impersonated US State Department officials to run app password phishing. The technique is simple but effective. The attacker convinces a target to set a specific app password on their account, one that the attacker already knows, and then uses it to log in without triggering two-factor authentication.
By October 2025, UNC6293 was still reusing screenshots from its June phishing lures, including the ms.state.gov reference, while only changing the surrounding text. By June 2026, the group had added OAuth phishing. After logging in to a legitimate service, victims were asked to share a URL or “verification code,” allowing attackers to obtain valid access tokens. The trick works because the login itself is legitimate, while the attackers hide the malicious step elsewhere.
UNC7005, tracked by Microsoft as STORM-2945, is a related but separate cluster first identified in February 2026. Google assesses it’s also connected to ICE RELIC, but notes it operates with lower technical sophistication and worse operational security than UNC6293. It compensates with a wider toolkit. UNC7005 runs app password phishing, device code phishing against both Microsoft and WhatsApp, malware distribution, and OAuth phishing operations, sometimes in the same month.
“UNC7005 also conducts device code phishing operations for both Microsoft and WhatsApp accounts.” continues the report. “The themes of these phishing waves often involve invitations for calls with individuals from notable organizations related to the target’s field or, most recently, invitations to diplomatic events and conferences. “
The GLOBSEC conference spoof is a useful illustration of how UNC7005 works. The actor built a landing page mimicking an invitation to the legitimate GLOBSEC forum in May 2026, collected detailed registration information from targets including, not for the first time in ICE RELIC-linked operations, a wine selection for a fictional dinner, and then presented a Microsoft device code for the target to enter. The registration form still contained a reference to “Embassy security policy” rather than GLOBSEC, a leftover from the previous lure template that the actor hadn’t cleaned up. When Google flagged the page quickly, UNC7005 revised the template within days, citing “technical difficulties” to explain the change to anyone still watching.
UNC7005 also used WhatsApp phishing pages to trick victims into linking their accounts to an attacker-controlled device. The fake pages offered options such as joining a call, opening an encrypted chat or downloading a file. If victims chose the call option, malicious JavaScript asked for microphone and camera access, recorded them, and sent the footage to the attackers.
In late May 2026, UNC7005 ran a broader phishing wave targeting US-based academics, diplomats, and Russia researchers. The lure was a fake “Summit Companion App” to read a document supporting Ukraine.
“In May and June 2026, UNC7005 conducted social engineering operations spoofing WhatsApp. The phishing pages distributed by the attacker lure targets into linking their WhatsApp accounts with an attacker controlled device in order to join a secure WhatsApp call, chat, or document share.” states the report. “The attacker also attempts multiple other methods of compromise after the device is linked.”
Windows users who downloaded it received VIDAR, an off-the-shelf infostealer sold as a service that pulls saved credentials, cookies, and payment data from browsers. Mac users received ATOMIC, also known as AtomicStealer, a macOS infostealer operating the same business model. Neither is custom tooling. The actor’s email address in this operation was nearly identical to one used by UNC6293 a year earlier.
The hospitality captive portal campaign, previously reported by Reliaquest and Microsoft and attributed to Midnight Blizzard, connects directly to UNC7005. Google traces the infrastructure back to April 2026: domains spoofing Microsoft authentication resources, which Google added to Safe Browsing blocklists as they appeared. By mid-July 2026, those same domains were receiving redirects from captive portals at hotels and conference centers. The IP resolution trail links the captive portal infrastructure to the GLOBSEC device code phishing operation and to ENGINELIGHT, a Go-based malware used in a separate limited UNC7005 operation in May 2026.
CHERRYPIE, also known as ChocoShell, is a PowerShell infostealer that adds another interesting detail. Google found comments and code references that appear consistent with AI-generated code, suggesting the attackers may be using an LLM to develop malware. The data it targets overlaps with the commercial infostealers already used by UNC7005, leading Google to suspect that CHERRYPIE could be a customized version of a malware-as-a-service tool.
UNC5976 is the third cluster and the most distinct. It focuses on military, aerospace, defense industrial base, and NGO targets, concentrating geographically on Ukraine and Armenia. Instead of residential proxies for post-compromise access, as UNC6293 and UNC7005 use, it runs dedicated infrastructure. Its OAuth phishing is more automated: the actor registers file-sharing-themed domains, creates Google Cloud projects behind them, and uses cloud-hosted scripts to collect authentication tokens from targets who log in through what looks like a Google sign-in prompt on a fake file-sharing page. Within three months of Google disrupting this infrastructure, UNC5976 had built at least twelve new domains and was already migrating toward non-Google hosting providers.
In April 2026, UNC5976 also distributed HEADRUSH, a malicious Excel plugin, through a domain impersonating a Ukrainian research institute, potentially targeting a Ukrainian aerospace and imaging company. HEADRUSH eventually leads to an HTA downloader, though Google wasn’t able to recover the full infection chain.
The defender challenge that runs through all three clusters is the same one Google names directly.
” The accounts these groups target are often personal, rather than corporate domain-joined accounts, creating a visibility gap for monitoring compromise from an organizational perspective. The likely use of encrypted messenger applications instead of email for initial outreach also presents a challenge to defenders hoping to track and remediate abuse.” concludes the report. “The combination of these tactics not only enables the attacker to conduct quick-turnaround exfiltration operations, but also presents opportunities for the attacker to further phish targets of interest from compromised, legitimate accounts. “
Security teams watching corporate email and endpoint telemetry won’t see the initial contact. By the time a compromised personal account starts being used to phish the target’s contacts, the original access event is already cold.
Google’s practical guidance for individuals: don’t set app passwords for anyone who asks, revoke existing ones you don’t recognize, check WhatsApp’s linked devices list, and treat any OAuth authorization prompt from an unsolicited message as suspicious regardless of how polished the surrounding page looks. High-risk individuals should consider Google’s Advanced Protection Program, which blocks app password creation entirely.
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers.
Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS and HTTP traffic on captive portal networks at hotels, conference centers, and shared venues worldwide to redirect guests toward malware and credential theft operations. If you connected to hotel Wi-Fi while traveling in the past few months, this report is worth reading carefully.
“Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945 manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure.” reads the report published by Microsoft. “To date, Microsoft has identified widespread compromise of Wi-Fi networks at hospitality-related organizations and other networks serviced by captive portal equipment in several countries. ReliaQuest has identified this activity not only at hotels, but also conference centers and other shared venues, and assesses that the goal of this activity is to access the accounts of corporate travelers.”
That last point matters: the shared infrastructure patterns suggest this may not be a series of individual venue compromises but rather access to something shared across portions of the captive portal ecosystem. Microsoft hasn’t named any provider.
The malware delivered through these networks is CornFlake, a full-featured Windows remote access trojan written in Go.
“CornFlake registers as a Windows service named svchost32 with the display name “Cloud Sync Service” and description “Synchronizes files with the cloud storage provider”, deliberately mimicking the legitimate svchost.exe process.” continues the report. “It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks, and a persistence watchdog routine that runs continuously to restore any persistence mechanism that is removed by defenders or endpoint protection.”
CornFlake establishes an encrypted C2 channel using ECDH P-256 key exchange and supports dynamic reconfiguration without redeployment. Once installed, the RAT can log keystrokes, monitor the clipboard, capture screenshots, audio and webcam feeds, steal browser credentials, exfiltrate files, monitor USB devices, collect detailed system information, and execute remote commands. It also exposes a local HTTP API, allowing companion malware such as ChocoShell to reuse its secure C2 channel for file theft, configuration updates, and connectivity checks.
“For command and control (C2), CornFlake performs an Elliptic Curve Diffie-Hellman (ECDH) P-256 ephemeral key exchange with the C2 server, derives a session key via SHA-256, and communicates over a custom JSON protocol framed within the encrypted channel.” states the report. “This provides an encrypted channel to the C2 server, with each C2 session using a unique ephemeral key, making decryption of captured traffic impossible without the session-specific private key. “
Each C2 session uses a unique ephemeral key, which means captured traffic can’t be decrypted without that session’s private key. The malware also supports a runtime configuration file that lets the attacker reconfigure C2 servers and targeting without redeploying the implant.
CornFlake is delivered via ClickFix-style pages that impersonate Windows Update screens, Google verification pages, DirectX installers, browser update prompts, and disk optimization utilities — whatever looks most plausible for the venue. The victim still has to execute the payload, but the captive portal controls exactly what they see when they try to connect. Microsoft also found indications that Storm-2945 may be targeting Android devices through the same landing pages, which include instructions to download and install an APK.
The second tool, ChocoShell, is a PowerShell infostealer that runs entirely in memory. Its primary target is credentials.
“ChocoShell collects Microsoft 365 and Azure Active Directory (AD) access tokens, refresh tokens, and Web Account Manager (WAM) tokens from .tbres files in the Token Broker cache. Collection of these tokens represents a significant threat to enterprise environments, as threat actors could replay SSO sessions without browser cookies.” states Microsoft. “Additionally, Wi-Fi credentials are harvested via netsh wlan show profile with key=clear.”
ChocoShell also implements three silent UAC bypass techniques with ordered fallback, disables Windows Defender signature updates, and uses Chrome DevTools Protocol to extract browser cookies by launching the browser with a remote debugging port. This technique bypasses Chrome’s App-Bound Encryption entirely.
Since July 16, some CaptiveCrunch landing pages have added device code phishing to the mix, redirecting guests into Microsoft’s legitimate device code authentication flow. The attacker initiates the authentication request and presents the user with a code to enter at Microsoft’s real sign-in page. When the user enters it, they authenticate the attacker’s session instead of their own — an MFA-satisfied session, since the user just completed the factor. Microsoft recommends blocking the device code flow through Conditional Access policies everywhere it isn’t explicitly required.
Researchers also detailed FruitStone, the web-based C2 panel used by Storm-2945 operators to manage the CaptiveCrunch campaign. It provides a centralized interface to control CornFlake implants, deploy payloads, collect stolen data, and manage compromised devices. Disguised as a legitimate “CloudSync Console,” it supports multi-operator access, agent monitoring, remote commands, file theft, credential collection, configuration updates, and campaign infrastructure management.
The practical advice for travelers is blunt: treat hotel, conference, and airport Wi-Fi as hostile. Use a mobile hotspot or cellular data instead wherever possible. Don’t download or execute anything a captive portal presents as an update, certificate, troubleshooting tool, or security utility. Don’t enter corporate credentials on venue registration pages. And if your organization hasn’t already blocked device code flow in Conditional Access, now is a reasonable time to check.
Recently, ReliaQuest’s threat research team also documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft login pages.
There’s a pattern connecting all this to previous campaigns. The tradecraft echoes a Russian-linked operation called FrostArmada, which hit home routers the same way earlier this year, and researchers tie both to the group known as APT28 (aka UAC-0001, aka Fancy Bear, Pawn Storm, Sofacy Group, Sednit, BlueDelta, and STRONTIUM). The link isn’t a smoking gun; it’s shared technique, not shared infrastructure, and the researchers say so plainly.
Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials.
ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft login pages. No phishing email required. No malicious attachment. Just bad luck about which hotel you picked.
“Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees.” reads the report published by ReliaQuest. “Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026.”
The mechanism is simple once you see it. These gateways handle DNS for every device that connects, so whoever controls the gateway controls where your traffic actually goes, even when the address bar looks completely normal. ReliaQuest found compromised devices across several US cities plus India and Saudi Arabia, hitting employees from finance, law, healthcare, energy, and retail, which tells you this isn’t aimed at one industry. It’s aimed at anyone who travels for work.
Researchers think the entry point was weak or reused admin credentials on internet-facing management interfaces, things like exposed SSH or web consoles.
“ReliaQuest assesses with low-to-medium confidence that initial access into these devices exploited exposed management interfaces (including internet-facing SSH, SNMP, and web administration consoles) in combination with weak or reused administrative credentials.” continues the report. “We encountered visibility constraints into the individual devices that prevented confirmation of this hypothesis, but this methodology would be consistent with the gateway targeting and DNS poisoning patterns documented in recent reporting on an APT28-linked campaign known as “FrostArmada.””
Once inside, the attackers pointed DNS toward domains built to look like Microsoft’s login pages, including m365-owa.com and ms365-live.com. The whole thing runs on trust, since a device joining a network just assumes the DNS resolver it’s handed is telling the truth.
That trust gets abused in a way that dodges the DNS protections people already have. Switching to a hardcoded resolver like 8.8.8.8 doesn’t save you, because the query still leaves the laptop unencrypted and the gateway can rewrite the answer before it ever reaches Google’s server. Encrypted DNS tools help only if they run in strict mode; the default “opportunistic” mode quietly falls back to plaintext the moment encryption fails, and that fallback is exactly what gets hijacked.
“Two configurations do stop it. A full-tunnel VPN routes all DNS through the corporate tunnel before the gateway can touch the request. Encrypted DNS in strict mode (DNS over HTTPS or DNS over TLS with plaintext fallback disabled) ensures the gateway can’t forge a response.” states the cybersecurity firm. “Most DNS encryption tools default to opportunistic mode, which permits plaintext fallback when encrypted resolution fails. That fallback is what the gateway redirects, making opportunistic mode insufficient; only strict mode closes the gap.”
ReliaQuest also caught something extra in about a third of cases: an attempt to abuse Windows’ automatic proxy discovery feature, known as WPAD.
WPAD is a Windows feature that automatically discovers proxy settings when a device connects to a network. In this campaign, attackers abused it by controlling DNS responses, potentially tricking Windows into loading a malicious proxy configuration. If successful, they could intercept traffic from browsers, authentication services, and enterprise apps. Because the traffic still uses HTTPS, the attack can blend in with normal network activity and be difficult to detect.
Pull that off and the attacker routes a much wider slice of an employee’s traffic, not just login attempts, through their own proxy. In a smaller number of cases, the attackers skipped credential theft entirely and went after Microsoft’s device-code sign-in flow instead, tricking users into approving a login they didn’t realize belonged to someone else. Approve that prompt and the attacker walks away with a valid, MFA-cleared session token, no password needed.
“In roughly one-third of observed cases—Windows devices that didn’t have Web Proxy Auto-Discovery (WPAD) disabled, or Mac devices—the attacker also attempted WPAD abuse. If successful, it routes all Windows application traffic through the attacker’s proxy, broadening the redirection surface well beyond authentication traffic.” continues the report. “This technique wasn’t documented in prior FrostArmada-linked reporting, making it one of the clearest distinctions between this campaign and previously observed APT28 activity.”
There’s a pattern connecting all this to previous campaigns. The tradecraft echoes a Russian-linked operation called FrostArmada, which hit home routers the same way earlier this year, and researchers tie both to the group known as APT28 (aka UAC-0001, aka Fancy Bear, Pawn Storm, Sofacy Group, Sednit, BlueDelta, and STRONTIUM). The link isn’t a smoking gun; it’s shared technique, not shared infrastructure, and the researchers say so plainly.
The fix is almost boringly simple, which is rare in this line of work. Force every corporate device onto an always-on VPN with full-tunnel routing, so DNS never touches the hotel network at all, and shut off split-tunnel exceptions that would let it sneak through anyway. Disable WPAD where nobody needs it, block Microsoft’s device-code flow at the identity provider unless someone has a real reason to keep it, and train people to check the certificate before they type a password on airport or hotel Wi-Fi.
None of this requires new budget or a six-month project. It requires someone actually flipping the switches that already exist.
Dutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine.
The Netherlands’ AIVD and MIVD, the civilian and military intelligence services, published a joint advisory on July 10 confirming that at least one Russian intelligence service is systematically compromising internet-connected IP cameras across the Netherlands, other EU and NATO member states, and Ukraine to collect military intelligence.
The operation is ongoing. The advisory is based on intelligence gathered by both services and covers a campaign that has escalated since Russia’s full-scale invasion of Ukraine.
The immediate military application in Ukraine is the most direct part of the finding.
“The information obtained by the Russian state actor via digital espionage operations targeting IP cameras provides insight into relevant military data, such as EU and NATO military transport routes and weapon deliveries to Ukraine. The Russian state actor uses image recognition software to conduct targeted searches for military vehicles and the military cargo they are transporting. In some cases, the access to IP cameras gained by the Russian state actor in Ukraine is used to identify the locations of Ukrainian military personnel.” reads the advisory. “Intelligence reveals that this information is subsequently used to neutralise Ukrainian military personnel and military materiel in use by the Ukrainian armed forces. Furthermore, the Dutch services have determined that the Russian service is using the access to IP cameras to acquire relevant military intelligence in EU and NATO member states, including information that is not directly relevant to the war in Ukraine.”
A roadside camera or a business camera overlooking a loading area becomes a targeting asset. That’s the direct line from a default password left unchanged to a strike on Ukrainian forces.
The surveillance operation in EU and NATO member states serves a different but related purpose.
“Furthermore, the Dutch services have determined that the Russian service is using the access to IP cameras to acquire relevant military intelligence in EU and NATO member states, including information that is not directly relevant to the war in Ukraine.” confirms the advisory. “To date, the Dutch services have not observed the Russian state actor using such information for military attacks outside Ukraine.”
The intelligence collected includes EU and NATO military transport routes and weapons deliveries bound for Kyiv. The Dutch services separately confirmed they caught a small number of cameras breached directly on military logistics routes inside the Netherlands, and warned the organizations running them so they could act.
The services are explicit that this isn’t a one-off campaign.
“The Dutch services assess that there has been a systematic increase in the number of digital espionage operations by Russian state actors to support military operations since the start of the war in Ukraine. The digital activities that target IP cameras form only a small part of their operations.” continues the joint advisory. “The Russian authorities derive significant tactical and strategic advantages from the deployment of cyber operations, from both defensive and offensive perspectives. For example, the MIVD has previously issued a warning about exploratory activities by Russian state actors targeting logistical routes, including routes in the Netherlands”
The camera surveillance is described as a small part of a much larger digital intelligence effort.
Getting into a camera isn’t technically sophisticated. The operators scan for internet-connected devices, fingerprint cameras by brand, and walk into those still running default passwords, outdated firmware, or factory settings. Once they’re in, image-recognition software runs automated searches through the video feed looking for military vehicles and the cargo they carry. No zero-days required.
“Once an IP camera has been identified, the malicious actor can attempt to gain access to the IP camera via the internet. This is often a relatively simple process, since many IP cameras that are connected to the internet lack adequate security measures.” states the advisory. “For example, they often have default passwords, obsolete firmware and factory configurations.”
The Dutch services have not observed the same camera-derived intelligence being used for military attacks outside Ukraine. But they say this demonstrates that Russia has the capability to do so, and that the same approach could be applied by Russian military units in a future conflict. That’s not a hypothetical being raised for rhetorical effect. It’s an assessment of demonstrated capability.
The most important variables, according to the advisory, are what the camera can see and whether it’s reachable from the public internet. On the first: cameras should be positioned for their actual purpose and should avoid covering logistics routes, loading docks, ports, or any area where military movements or weapons shipments pass. Sensitive zones within the field of view should be masked or blurred where possible, and GPS location data should be stripped from video streams.
On accessibility: live streams should not be publicly reachable unless there’s an essential reason for it. Port forwarding and UPnP should be disabled. Remote access should go through a VPN rather than direct exposure. Default passwords should be changed immediately on installation, admin accounts should be kept separate from stream-viewing accounts, and MFA should be enabled wherever the device supports it. The advisory also flags the origin of the hardware itself: China, Russia, and Iran are cited as countries actively running offensive cyber programs targeting Dutch and European interests, and buyers should factor that into procurement decisions.
Cybersecurity firm Censys counted more than 87,000 internet-connected cameras across EU and NATO countries and Ukraine running services matching known-exploited vulnerabilities. In the Netherlands alone, more than 45,000 cameras are reachable from the public internet.
The numbers illustrate the scale of the exposed surface the advisory is addressing. Fixing it doesn’t require new technology. It requires treating a camera pointing at a transport route with the same security discipline as any other system connected to the internet.
Chinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms.
Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A single HTTP header fingerprint on port 1111 led them to 13 Hong Kong-based servers and, on one of them, an open directory containing 2,431 files and 80 subdirectories: victim source code, custom exploit scripts, cloned login pages, and operator logs with notes written in Simplified Chinese. Someone left the door open. Researchers walked right in.
What made this find unusual wasn’t just the scope of the targeting. It was the tooling.
“What caught our attention was the tooling behind it. Claude Code and DeepSeek-v4-pro ran as working parts of the intrusion, not tools off to the side. They handled reasoning for bypass techniques, reworked exploits after failed attempts, and built the phishing pages used to harvest credentials.” reads the report published by Hunt.io. “That puts this campaign alongside Anthropic’s November 2025 disclosure of a China-linked operation that used Claude Code to automate large-scale intrusions.”
This puts the campaign alongside Anthropic’s own November 2025 disclosure of a China-linked operation that used Claude Code to automate large-scale intrusions.
The campaign resembles another China-linked operation that Anthropic disclosed in November 2025, where attackers also used Claude Code to automate large-scale intrusions.
The recovered logs show that the attackers split the work between two AI models. Claude Code 2.1.165 handled execution by running Bash commands, managing long-running sessions, carrying out tasks in parallel, and creating phishing infrastructure. DeepSeek-v4-pro handled the planning by generating scripts, choosing attack techniques, and finding new ways to bypass defenses when earlier attempts failed.
“DeepSeek-v4-pro operates as the underlying reasoning model, handling attack logic, script generation, and decision-making.” continues the report. “In short, offensive logic is routed through a Chinese domestic LLM while leveraging Anthropic’s agentic execution infrastructure.”
A recovered CLAUDE.md file also contained instructions telling Claude Code to automatically create, test, and improve cloned phishing pages for multiple targets.
Session IDs in the logs confirmed the same infrastructure was used across different country-specific campaigns, with Taiwan operations saved to dedicated working directories. Timestamps on the files span June 8 through 12, 2026, and the three servers sharing SSH keys were actively maintained as recently as June 18-19, when all three reissued their ARL certificates together.
In Thailand, attackers used SQLMap to exploit a government administrative system through SQL injection, gained admin panel access, and deployed a web shell disguised as a GIF file for persistent command execution. The exfiltrated database held the names, national ID numbers, and job titles of government employees. The directory contained 980 files referencing this system alone, suggesting a lengthy and focused operation. Test entries the attackers created during the intrusion confirmed they had hands-on, interactive access to the data, not just automated extraction.
In Afghanistan, a government web application handling citizen complaint submissions was compromised. The attackers extracted source code, database credentials, encryption keys, and mail infrastructure code from a Laravel 5.8.38 installation, then used those credentials to build a custom Python exploit targeting Laravel’s deserialization mechanisms. Six distinct copied versions of the complaint submission form appeared in the directory. For a state actor, access to a live channel where citizens report grievances against government and institutions is a particular kind of intelligence prize.
In Taiwan, eight organizations in supply chain and defense-adjacent sectors were mapped and fingerprinted, with two successfully exploited. A chemical manufacturer was hit through SQL injection. A telecom and edge device manufacturer was compromised after attackers found hardcoded Supabase keys and Azure Logic App tokens in publicly accessible JavaScript files, giving them direct access to cloud infrastructure accounts. The reconnaissance script targeting these organizations ran DNS brute-forcing, certificate transparency queries, and HTTP service fingerprinting with an emphasis on VPN gateways, GitLab instances, and Jira environments.
The United States appeared at earlier stages of the operation rather than as a confirmed breach. NASA hosts launchpad.nasa[.]gov and ngis.nasa[.]gov were logged in network scanning output but not pursued further. Cloned pages impersonating the D.C. Council and Delaware County, Pennsylvania were recovered at varying levels of completion: the D.C. Council WordPress admin login page was fully built while the homepage was still missing images.
Hunt.io assessed the targeting of mid-tier government administrative bodies as consistent with documented Chinese intelligence collection priorities around procurement, vendor relationships, and policy visibility. The county contact form clone, specifically built to capture citizen submissions, fits that same pattern.
A parallel campaign hit financial services firms across Europe, Australia, and Asia. A CORS exploit page on one of the attacker-controlled servers successfully extracted WordPress administrator credentials from a large payment processing platform, with LinkedIn cross-referencing confirming the extracted account names matched real employees.
“In addition to the government-sector activity, the operators ran a parallel campaign against financial services firms across multiple regions. The clearest example being an attacker-developed CORS exploit page on 112.213.124[.]159 that successfully extracted WordPress administrator account data from a large payment processing platform.” states the report. “A cross-reference on the exposed accounts against public LinkedIn profiles, confirmed individuals with the same name as employees of the company.”
The 13 servers are all in Hong Kong, spread across four hosting providers: VMISS Inc., MEGA-II IDC, CTG Server Limited, and Antbox Networks Limited. Three share SSH host key fingerprints and ran identical ARL reconnaissance software serving the same default TLS certificate, with fields pointing to Shanghai. Two servers in the cluster also presented certificates self-identifying as “Gshell C2,” a previously undocumented C2 framework. Because those two servers overlap with the TencShell cluster, Hunt.io assesses with moderate confidence that Gshell is a second C2 framework operated in parallel by the same actors.
The malware recovered from the delivery ports was a previously unreported Linux/ARM 32-bit binary that communicates back to the same infrastructure hub over WebSocket. It’s capable of extracting Tencent QQ messaging credentials including SDK identifiers and cryptographic keys, enterprise messaging platform tokens, and cloud service access keys. A separate Linux/x86 variant uses the Go obfuscation tool garble to strip function names, but both variants share an identical 80-byte encryption key, pointing to a shared codebase across architectures.
“The campaign reflects an intermediate-to-advanced capability set: custom exploit development aimed at specific framework versions, multi-platform malware variants, and integration of LLMs for real-time attack assistance.” concludes the report. “Observable indicators: Simplified Chinese in code and documentation, Hong Kong infrastructure clustering, and multi-continent targeting, are consistent with China-based threat actor activity.”
Hunt.io notified the affected organizations and national CERTs on July 6, 2026, and held publication for a seven-day disclosure window. The full indicator set, including file hashes and network infrastructure, is in the original report.
FBI warns Russian spies now target Signal Backup Recovery Keys, enabling access to message history and long-term account takeover.
The FBI and CISA updated their March 2026 warning about Russian intelligence phishing campaigns, and the new advisory adds a detail that wasn’t in the original: the operators have shifted their primary objective from stealing verification codes to stealing Signal Backup Recovery Keys.
The March warning covered FSB-linked groups targeting government officials, military personnel, journalists, and Ukrainian officials through fake Signal support messages. The June update gives those groups public tracking names: UNC5792 and UNC4221, both linked to Russian Federal Security Service officers including those embedded with FSB Border Guards and others working on behalf of Russian military services.
“RIS cyber threat actors have compromised individual CMA accounts, but not the CMA’s encryption or the application itself. To date, this activity has been publicly tracked as UNC5792 and UNC4221.” reads the PSA alert published by the FBI.. “RIS cyber threat actors continue to masquerade as automated CMA support accounts in updated phishing messages but have evolved their tactics to attempt to elicit victims’ Backup Recovery Keys.”
The earlier version of this campaign asked targets for SMS verification codes, account PINs, or tricked them into clicking doctored group invite links that silently linked an attacker’s device to the account. The new version is more damaging. The phishing message walks the target step by step through enabling Signal backups, navigating to the Recovery Key, and pasting it into the chat. Two sample messages are printed in the advisory: one dressed as a mandatory two-factor rollout announcement, the other as an urgent data recovery warning claiming messages are at risk of permanent loss.
The Recovery Key is what makes this particularly serious.
“RIS cyber threat actors continue to elicit victims’ verification codes and account PINs (see Figure 1). If a targeted user backs up their CMA messages as directed in Figure 1 and later provides their Backup Recovery Key (see Figure 2), RIS cyber threat actors can view the account’s historical messages, private and group messages, and take over the victim’s account.” continues the alert.
A backup recovery key doesn’t just unlock one session. It unlocks the entire message archive, and unlike a stolen code that expires, this key keeps working.
“If a victim inadvertently shares their Backup Recovery Key, that same key remains valid even if they create a new account following the compromise using the same phone number.” continues the report. “Consequently, the actor could potentially use the compromised key to take over the new account in the future as well.”
Making a new account doesn’t help if the old key still works against it. The only fix is generating a new key through Settings, which invalidates the old one for future backup downloads. That doesn’t recover anything the attacker already pulled, and the advisory is clear about that.
The FBI and CISA are unambiguous on one point that tends to get lost in coverage of these incidents: none of this breaks Signal’s encryption or the application itself. The attackers aren’t cracking anything. They’re walking through a legitimate feature with a key the user handed them, which is a completely different problem with a completely different solution.
Alongside the advisory, the State Department’s Rewards for Justice program announced it’s offering up to $10 million for information on UNC5792. The activity overlaps with warnings issued earlier this year by Dutch intelligence, Germany’s BfV and BSI, and France’s ANSSI, and it builds on Google Threat Intelligence Group’s documentation of UNC5792 abusing Signal’s linked-device feature in early 2025. The same tradecraft has since been observed against WhatsApp and Telegram.
For anyone using Signal who works in government, security, journalism, or military-adjacent roles, the advisory’s guidance is direct. Treat any in-app message claiming to be Signal support as hostile: real support doesn’t contact users inside the app to ask for codes, PINs, or Recovery Keys.
Open Settings, check Linked Devices, remove anything unrecognized. If you think you handed over your Recovery Key at any point, generate a new one now and assume anything backed up before that moment is already in someone else’s possession.
The encryption holds. The account is the weak point, and the advisory makes clear that the targeting is deliberate, sustained, and still active.
“To mitigate this risk, the user must generate a new Backup Recovery Key within the Settings control; this action will invalidate the previous key for all future backup downloads. However, please note that this does not prevent the actor from having already downloaded a backup of the original account.” concludes the alert.