♡Follow0 Attack Groups Russian Hackers Exploit Google OAuth and WhatsApp Linking in Multi-Platform Account Hijacking Campaigns Suspected Russian cyber espionage groups are abusing legitimate authentication flows, including Google OAuth and WhatsApp device linking, to hijack accounts across Europe… AiTM AMOS app password phishing APT29 August 20, 2026
♡Follow0 Attack Groups UNC5976: Russian Threat Actor Automating OAuth Token Theft via Cloud Infrastructure UNC5976 is a suspected Russian threat actor active since at least March 2026, using OAuth phishing and automated token collection. It creates… Cloud Infrastructure HEADRUSH OAuth phishing token theft August 20, 2026
♡Follow0 Malware HEADRUSH: Rogue Excel Plugin Delivering HTA Malware HEADRUSH is a rogue Excel plugin used by UNC5976 to deliver an HTML Application (HTA) download. Discovered in April 2026, it is… Excel plugin HEADRUSH HTA Ukraine August 20, 2026