TL;DR what: Google Threat Intelligence Group detailed three suspected Russian espionage clusters, UNC6293, UNC7005, and UNC5976, that phish authentication flows rather than passwords, using OAuth consent, application specific passwords, device code grants, and WhatsApp device linking. Google Thr...
Source: [Dev.to](https://dev.to/etairos/three-russian-clusters-are-phishing-auth-flows-not-passwords-oauth-app-passwords-and-whatsapp-mi5)