Skip to main content

Threat Researchers Find State-Linked Clusters Hijacking Accounts through WhatsApp Device Linking and OAuth Abuse

STATUS: Active Espionage Campaign SEVERITY: 7/10 AUDIENCE: Government, Defense, Critical Infrastructure Security Leads   

Aug 28, 2026

·

Blog

·

Secure Communications

New threat intelligence research identifies three separate state-linked clusters hijacking accounts belonging to government, defense, academic, and think tank personnel across Europe and the United States, using legitimate WhatsApp and Google account features rather than breaking any encryption.

What Happened and Why It Is Different 

The encryption held. The account boundary did not.

Google Threat Intelligence Group has identified three separate state-linked espionage clusters, tracked as UNC6293, UNC7005, and UNC5976, abusing legitimate authentication features to hijack accounts belonging to government, defense, aerospace, academic, and think tank personnel across Europe and the United States.1

One cluster's method is the sharpest example. Targets are lured to a page posing as an invitation to a secure call, chat, or document share. The page asks for a phone number, then walks the victim through WhatsApp's own device linking flow: scan a QR code, enter a linking code, approve a new device. Once linked, the attacker's device sits inside the victim's real WhatsApp account. From there the attacker can join encrypted calls, read chats, or push the victim toward a second compromise, either a credential harvest page or a file download carrying malware.1

A related campaign, tracked separately as CaptiveCrunch, targets travelers instead of individuals. Captive Wi-Fi portals in hotels, conference centers, and airports get hijacked, in some cases through compromised managed service providers with administrative access to the Wi-Fi gateways. Guests connecting to what looks like the hotel network get redirected through attacker infrastructure, either to steal credentials through a fake Microsoft sign-in prompt or to deliver malware disguised as a routine software update2. Lumen Black Lotus Labs' independent tracking of the same activity has raised the possibility that the threat actor compromised several managed service providers directly, then abused the trust relationship with their clients to reach the Wi-Fi gateways.3

The same pattern shows up in the OAuth phishing run by the other two clusters. Victims complete a real Google login. The account gets reassigned to the attacker afterward, through a stolen token, not a stolen password.1

What They Found and What It Means 

Finding
What It Means
Operational Consequence
Open Question
Three clusters abuse legitimate authentication features, including WhatsApp device linking and Google OAuth sign-in, to hijack accounts.
The vulnerability isn't in the cryptography. It's in how each platform decides which device is allowed to represent the account holder.
An account can be fully compromised without a single password, certificate, or encryption key ever being broken.
How many other multi-device or account-recovery features carry the same unauthenticated trust assumption.
CaptiveCrunch hijacks captive Wi-Fi portals in hotels, conference venues, and airports, in some cases through compromised managed service providers.
The attacker does not need to compromise the traveler's device directly. Compromising the network the traveler trusts is enough.
Personnel who took no risky action beyond connecting to what looked like the venue Wi-Fi can still be redirected to credential theft or malware.
How many other MSP-managed Wi-Fi deployments carry the same single point of administrative compromise.

Why This Matters

Old Assumption
Current Reality
BlackBerry Response
If a messaging app uses end-to-end encryption, the account behind it is secure.
The encryption held in every case here. The attacker got in by adding an authorized device through the app's own linking flow, not by breaking the cipher.
BlackBerry® SecuSUITE® enrollment is administered by the organization. There is no public device-linking flow for an outsider to spoof.
Hotel, conference, and airport Wi-Fi is a minor inconvenience, not a security boundary.
CaptiveCrunch shows that compromising the network a traveler trusts, sometimes through the managed service provider running the venue's Wi-Fi, is enough to redirect them into credential theft or malware.
BlackBerry® AtHoc® gives traveling personnel an alerting channel that doesn't depend on trusting whatever network they're currently connected to.
Standard endpoint protection and login-time MFA are enough to stop credential theft.
The malware observed here targets live session tokens and stored credentials after login, not the login screen itself.
BlackBerry® UEM® device compliance and app-level control shrink the space where a phished token or an update-disguised payload can operate.
IMMEDIATE 
Audit linked devices on any account using WhatsApp, Signal, or a similar app with self-service device linking. Treat an unrecognized linked device as a live compromise, not a stale session. 
IMMEDIATE 
Flag unsolicited OAuth “confirm sign-in” or verification code requests as compromise attempts by default, regardless of how legitimate the requesting domain looks.
SHORT-TERM 
Extend network trust review to personnel traveling through hotels, conference venues, and airports, particularly where Wi-Fi is managed by a third party.
SHORT-TERM 
Pair authentication hardening with a communications channel whose enrollment the organization controls directly, not one open to any device that can scan a code.
ONGOING
Track whether session-revocation and token-lifetime policies are aggressive enough to limit the value of a credential or token stolen after login.

BlackBerry Secure Communications Position

A messaging app can keep its encryption promise perfectly and still hand an account to an attacker, because the weak point here was never the cipher. It was the question of which device gets to speak for the account holder, and a self-service linking flow answers that question with less scrutiny than a login screen ever would. For any organization coordinating sensitive activity, that boundary has to be administered by the organization, not left open to whichever device can scan a code.

Citations:

  1. Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts (The Hacker News, coverage of the Google Threat Intelligence Group findings, August 20, 2026).

  2. CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft (Microsoft Security Blog, CaptiveCrunch campaign analysis, July 31, 2026).

  3. CaptiveCrunch Part ll: Supply Chains and Other Adventures in WIFI (Lumen Black Lotus Labs, CaptiveCrunch supply-chain analysis, August 20, 2026).

Get updates about the latest in-depth knowledge for secure communications.

Industry Discussion

On-Demand Webinar: What CI Fortify Doesn't Say About Communications

In July, CISA and other agencies released joint guidance titled "CI Fortify – Advice for Isolating Vital Systems," directing critical infrastructure operators to proactively isolate vital OT systems from unreliable third-party networks and sustain essential operations independently. Join us for an informative session about what CI Fortify asks operators to do, what it costs, and what it leaves unaddressed.

Watch now