Russian-linked hackers abuse Google OAuth and WhatsApp linking to hijack accounts
THE BRIEF
Three suspected Russian cyber-espionage clusters have been observed abusing legitimate Google OAuth and WhatsApp device-linking workflows to target people in government, defence, aerospace, academia and think tanks across Europe and the United States. Rather than relying only on obviously malicious login pages, the operators exploit trusted authentication and account-linking processes to persuade targets to grant access or connect attacker-controlled sessions. This makes the activity harder to distinguish from normal user behaviour and illustrates a broader shift toward identity attacks that weaponize legitimate platform features. Organizations supporting high-risk users should review OAuth grants, linked-device activity and unusual session creation while strengthening user guidance around unexpected authorization prompts.
WHY IT MATTERS
Identity compromise increasingly happens without stealing a password in the traditional sense. OAuth consent, QR/device linking and delegated access can give attackers durable access while bypassing some controls designed around credential theft. For banks, governments and other high-value organizations, the lesson is that identity telemetry must cover token grants, device enrollment and session changes as well as failed logins. The campaign also reinforces the value of rapid revocation procedures for suspicious app permissions and linked devices, particularly for executives and staff exposed to state-backed targeting.
WHO SHOULD CARE
Identity and access teams, SOCs, government and defence organizations, financial institutions, executive-protection teams and users with elevated geopolitical exposure.
WHAT TO DO NOW
- Review unusual OAuth grants and recently linked WhatsApp devices for high-risk users.
- Restrict third-party application consent where business requirements allow.
- Alert on new device/session creation from unusual geographies or infrastructure.
- Train targeted personnel to treat unexpected authorization and device-linking requests as phishing events.
- Maintain a rapid process to revoke tokens, sessions and linked devices after suspected compromise.
VERIFICATION NOTE
Verified against the cited source; claims are summarized conservatively and attacker assertions are identified as unconfirmed where applicable.