Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S.

These clusters include UNC6293, UNC7005, and UNC5976.

"These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms," Google Threat Intelligence Group (GTIG) researchers Gabby Roncone and Wesley Shields said in a report published today.

UNC6293, first detailed by the tech giant and the Citizen Lab in June 2025, is assessed to be a sub-cluster of Ice Relic (formerly APT29), which is also tracked under the monikers Cozy Bear and Midnight Blizzard. The hacking crew was previously attributed to a campaign that abused a Google account feature called application specific passwords to seize control of victim accounts.

Since then, the threat actor has continued to engage in phishing campaigns that tend to be small in scope, targeting fewer than five users at a time, while impersonating State Department officials to perform app password phishing. The application names and lures revolve around diplomatic themes and upcoming conferences or meetings, some of which were highlighted by Volexity in December 2025.