Google Researchers Identified Russian Threat Groups

Intelligence teams traced 33 network indicators linked to three distinct threat actors targeting specific individuals.

Updated on Sept. 21, 2026 in Cybersecurity

Google Researchers Identified Russian Threat Groups

Live Poll

Do you trust that your personal or business domains are protected from malicious threat groups?

The Google Threat Intelligence Group has identified three Russian threat groups, designated as UNC6293, UNC7005, and UNC5976, that are actively targeting specific individuals. Researchers confirmed these actors are associated with 33 specific network indicators of compromise.

Why it matters

This identification provides security teams with concrete network signatures to defend against targeted intrusions. The research highlights the ongoing use of domains and IP addresses by these groups to facilitate unauthorized communications.

The analysis uncovered 33 indicators of compromise, including 26 domains and five IP addresses, identified using tools like the WhoisXML API MCP Server. Between 5 April and 23 August 2026, 317 unique IP addresses communicated with these indicators.

The players

Google Threat Intelligence Group

An internal division at Google that tracks global cyber threats and develops detection signatures for network defense.

The details

Researchers employed the WhoisXML API MCP Server, a platform for querying DNS and domain registration data, to cross-reference potential malicious infrastructure. By querying indicators against the Bulk Registration Risk API, WHOIS API, and DNS Chronicle API, the team isolated 26 domains managed by seven registrars. These domains, which were registered between 27 June 2024 and 12 August 2026, serve as the infrastructure for the threat actors' network activity.

Timeline

  1. 27 June 2024: The earliest domain indicator of compromise was created.

  2. 20 November 2025: The domain miov2iaiaoubqosiqoiajwowiwjso.online was created.

  3. 5 April 2026 to 23 August 2026: 317 unique victim IP addresses communicated with five IP indicators.

  4. 7 July 2026: A client IP address communicated with the malicious domain globsec.net.

The Tech Race

This discovery extends the established threat intelligence mapping of Russian state-aligned cyber campaigns by cataloging specific infrastructure used by three distinct actors. It follows a pattern set by previous campaigns identified by the Google Threat Intelligence Group.

Security administrators and incident responders should audit their logs for the 33 newly identified domain and IP indicators of compromise. These findings enable network teams to proactively block communications with the identified Russian threat infrastructure.

The takeaway

The research provides a actionable baseline for identifying intrusions related to UNC6293, UNC7005, and UNC5976. Security teams should monitor internal logs for the 33 specific network indicators flagged in the report to harden their perimeters.

Further reading

For more on evolving threat landscapes, visit our Cybersecurity section.

Source note: This article includes information reported by CircleID.

Live Poll

Do you trust that your personal or business domains are protected from malicious threat groups?