Attackers Use Real Google and Microsoft Authentication Before Redirecting Victims. Google says three Russia-linked espionage clusters are abusing legitimate Google and Microsoft authentication flows to steal tokens and account access from defense, government, academic and think tank targets, exposing a visibility gap around personal accounts.
First seen on govinfosecurity.com
Jump to article: www.govinfosecurity.com/that-legitimate-oauth-login-might-be-russian-hack-a-32634
![]()

