Validin Uses Infrastructure Pivots to Track Russian Cyber Espionage Clusters

Summary
Validin analyzes domains and hosting linked to Russian cyber espionage clusters, using historical DNS, registration data, HTTP responses, certificates, and other pivots to identify candidate infrastructure and explain confidence limits.
Key points
- The analysis builds on Google Threat Intelligence Group reporting about Russian espionage clusters targeting people in academia, think tanks, and other organizations in Europe and the United States.
- For UNC6293, Validin linked two additional domains to a registrant email associated with a known lure domain; the relationships are presented as candidate infrastructure, not confirmed attribution.
- HTML and CSS similarities, possible origin IPs, and host responses indicating possible Evilginx configurations provided further infrastructure pivots.
- For UNC7005, DNS history connected a phishing domain to related infrastructure, while changes in server headers suggested one IP may have changed hands.
- Title and header-hash searches, favicon hashes, certificates, and registration similarities surfaced additional domains, with filtering used to separate stronger candidates from likely incidental overlaps.
- The article cautions that many identified domains and IPs may be unrelated and recommends validating candidate links and monitoring low-confidence registration pivots.
Article Details
- Attack Vectors
- UNC6293 used foreignrelations[.]us and dosportal[.]app as lures for OAuth phishing.
- UNC7005 reportedly used Microsoft device-code phishing and device-code phishing targeting WhatsApp accounts.
- my-invite[.]org facilitated phishing through links in email.
- statistic-ms[.]live redirected visitors to an Ad Manager login prompt at https[:]//ad-g[.]org/login.
- UNC5976 used drive[.]google[.]verify-drive[.]com in an OAuth phishing campaign.
- Several subdomains of stateaffairs[.]us and the-washington-ballet[.]com showed possible Evilginx configurations and redirected visitors to legitimate websites.
- Defensive Notes
- Use historical DNS, host responses, certificates, registration records, HTTP headers, CSS similarities, and favicon hashes to identify and evaluate related infrastructure.
- Treat infrastructure discovered through pivots as candidates requiring verification; the article notes that some overlaps may be incidental or unrelated.
- Monitor the low-confidence registration-pivot domains supportnoreplay[.]com, security-forms[.]com, noreplaysupport[.]com, and info-forms[.]com for future use.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | dosportal[.]app | UNC6293-associated domain used as an OAuth phishing lure. |
| DOMAIN | drive[.]google[.]anticorruption[.]eurcpa[.]org | Listed as suspected campaign-related phishing infrastructure with hosting and content similarities. |
| DOMAIN | drive[.]google[.]formshare[.]cloud | Listed as suspected campaign-related phishing infrastructure with hosting and content similarities. |
| DOMAIN | drive[.]google[.]linkfileshare[.]net | Domain identified via registration pivot and listed as a suspected campaign-related phishing indicator. |
| DOMAIN | drive[.]google[.]sharedfolders[.]app | Listed as suspected campaign-related phishing infrastructure with hosting and content similarities. |
| DOMAIN | drive[.]google[.]sharedfolders[.]org | Listed as suspected campaign-related phishing infrastructure with hosting and content similarities. |
| DOMAIN | drive[.]google[.]sharefolders[.]org | Listed as suspected campaign-related phishing infrastructure with hosting and content similarities. |
| DOMAIN | drive[.]google[.]usercontent[.]app | Listed as suspected campaign-related phishing infrastructure with hosting and content similarities. |
| DOMAIN | drive[.]google[.]usercontent[.]online | Listed as suspected campaign-related phishing infrastructure with hosting and content similarities. |
| DOMAIN | drive[.]google[.]verify-drive[.]com | Domain used in an OAuth phishing campaign attributed by GTIG to UNC5976. |
| DOMAIN | eurcpa[.]org | Listed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster. |
| DOMAIN | fileshareapp[.]org | Net-new domain listed as suspected campaign-related infrastructure with valid certificates and similar HTTP content. |
| DOMAIN | fllefolder[.]com | Listed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster. |
| DOMAIN | foreignrelations[.]us | UNC6293-associated domain used as an OAuth phishing lure. |
| DOMAIN | formshare[.]cloud | Listed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster. |
| DOMAIN | info-forms[.]com | Low-confidence registration pivot listed for monitoring; its relationship to the campaigns could not be confirmed. |
| DOMAIN | internationalaffairsportal[.]us | Domain associated by registrant email and registration timing with UNC6293-associated infrastructure; listed as a suspected related indicator. |
| DOMAIN | linkfileshare[.]net | Domain identified via registration pivot and listed as a suspected campaign-related indicator. |
| DOMAIN | ms365-live[.]com | Related domain sharing DNS-history overlap with the IP address used by my-invite[.]org. |
| DOMAIN | my-invite[.]org | Actor-controlled domain reported by GTIG as facilitating phishing through email links. |
| DOMAIN | noreplaysupport[.]com | Low-confidence registration pivot listed for monitoring; its relationship to the campaigns could not be confirmed. |
| DOMAIN | security-forms[.]com | Low-confidence registration pivot listed for monitoring; its relationship to the campaigns could not be confirmed. |
| DOMAIN | sharedfolders[.]app | Listed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster. |
| DOMAIN | sharedfolders[.]org | Listed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster. |
| DOMAIN | sharefolders[.]org | Listed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster. |
| DOMAIN | stateaffairs[.]us | Domain associated by registrant email and registration timing with UNC6293-associated infrastructure; subdomains showed possible Evilginx configuration. |
| DOMAIN | statistic-ms[.]live | Domain that redirected visitors to a login prompt at ad-g[.]org. |
| DOMAIN | supportnoreplay[.]com | Low-confidence registration pivot listed for monitoring; its relationship to the campaigns could not be confirmed. |
| DOMAIN | the-washington-ballet[.]com | Lookalike domain with possible Evilginx configuration and infrastructure similarities to the dosportal[.]app decoy. |
| DOMAIN | usercontent[.]app | Listed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster. |
| DOMAIN | usercontent[.]online | Listed as suspected campaign-related infrastructure with hosting and content similarities to the phishing cluster. |
| DOMAIN | verify-drive[.]com | Domain associated with the drive[.]google[.]verify-drive[.]com phishing infrastructure. |
| IPV4 | 104[.]194[.]159[.]150 | IP address to which the phishing domain my-invite[.]org resolved. |
| IPV4 | 151[.]236[.]15[.]213 | Possible origin IP for Cloudflare-fronted domains with CSS similarities to the dosportal[.]app decoy. |
| IPV4 | 185[.]158[.]250[.]155 | Possible origin IP for Cloudflare-fronted domains with CSS similarities to the dosportal[.]app decoy. |
| URL | hxxps[:]//ad-g[.]org/login | Login-prompt URL to which statistic-ms[.]live redirected visitors. |
MITRE ATT&CK
Threat Actors
UNC5976GTIG-attributed cluster reported to use drive[.]google[.]verify-drive[.]com in an OAuth phishing campaign.UNC6293GTIG-attributed cluster reported to use foreignrelations[.]us and dosportal[.]app as OAuth phishing lures.UNC7005GTIG-tracked cluster reported to use Microsoft device-code phishing and device-code phishing targeting WhatsApp accounts.
Vendors
Products
Tools
Countries
Industries
Academia(GTIG) published research on several Russian cyber espionage threat clusters targeting individuals in academia, at think tanks, and in other organizations across Europe and the United States.Think tanksresearch on several Russian cyber espionage threat clusters targeting individuals in academia, at think tanks, and in other organizations across Europe and the United States.