UNC7005 (Storm-2945): Russian Espionage Group Abusing WhatsApp and OAuth
August 20, 2026
UNC7005, also known as Storm-2945, is a suspected Russian threat actor identified in February 2026. It targets academia, diplomatic, and nonprofit personnel in Ukraine, Western Europe, and the U.S. Uses device code phishing for Microsoft and WhatsApp, spoofing WhatsApp to link attacker devices. Also deploys infostealers like Vidar and Atomic, and conducts OAuth phishing via domains spoofing the Finnish Operations Center. Linked to CaptiveCrunch campaign.