CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

UNC5976: Russian Threat Actor Automating OAuth Token Theft via Cloud Infrastructure

August 20, 2026

UNC5976 is a suspected Russian threat actor active since at least March 2026, using OAuth phishing and automated token collection. It creates fake file-sharing domains and cloud projects to steal authentication tokens. Also distributes the HEADRUSH Excel plugin to deliver HTA malware, targeting military, aerospace, and NGOs, with focus on Ukraine and Armenia.