All Blogs

Inhospitable: Tracking Russian Cyber Espionage Infrastructure

Hunting methods to discover, validate or rule out, and track Russia-aligned cyber espionage threat clusters

 Kenneth Kinion · August 26, 2026 · 9 min read
Inhospitable: Tracking Russian Cyber Espionage Infrastructure

Hunting methods to discover, validate or rule out, and track Russia-aligned cyber espionage threat clusters

On August 20, 2026, the Google Threat Intelligence Group (GTIG) published research on several Russian cyber espionage threat clusters targeting individuals in academia, at think tanks, and in other organizations across Europe and the United States.

In this post, I’ll expand on infrastructure associated with these clusters to identify likely related domains, highlighting a handful of key pivots, search queries, and tracking methods that can be used to discover, validate or rule out, and track additional infrastructure.

UNC6293

GTIG notes that UNC6293 used the domain names foreignrelations[.]us and dosportal[.]app as a lure to facilitate OAuth phishing attacks.

Validin’s historical DNS database contains history for foreignrelations[.]us dating to 2021. During this time, Validin attempted to resolve the domain daily for years until began resolving on November 21, 2025 (the day it was registered, presumably for use by UNC6293).

Figure 0. Historical DNS for foreignrelations[.]us shows years of inactivity before being registered and activated on November 21, 2025.

Figure 0. Historical DNS for foreignrelations[.]us shows years of inactivity before being registered and activated on November 21, 2025.

In the ensuing months, Validin regularly tracked host responses, certificates, and registration details. Notably, Validin’s historical WHOIS collection shows that the registrant email address given956[@]2200freefonts[.]com was associated with two other domain names not in the report:

  • internationalaffairsportal[.]us
  • stateaffairs[.]us

Note that these two domains were both registered through Dynadot, Inc. around the same time as foreignrelations[.]us.

Figure 1. Registered domain names associated with the email address given956[@]2200freefonts[.]com.

Figure 1. Registered domain names associated with the email address given956[@]2200freefonts[.]com.

I don’t believe that the domain name 2200freefonts[.]com is owned or managed by UNC6293, but note that the domain was added to nearly a dozen block lists about a month before the UNC6293-associated domains were registered using an email address from that domain.

Figure 2. Validin’s reputation history showing 2200freefonts[.]com being added to email domain block lists on October 31, 2025.

Figure 2. Validin’s reputation history showing 2200freefonts[.]com being added to email domain block lists on October 31, 2025.

Copies and Proxies

The content in Validin’s archived host responses for the lure foreignrelations[.]us references the article “Everything, Everywhere, All at Once: The Future of U.S. Strategy” from the Council on Foreign Relations website.

I identified a small number of domain names and IP addresses that also include the <meta> tag <meta property="fb:app_id" content="1202896923085736"> (Validin search: ::"fb:app_id"::"1202896923085736"). This meta tag also appears on the legitimate website for the Council on Foreign Relations. While most of these domains and IPs are unlikely to be related to UNC6293, the IP addresses and domains on this list may warrant additional follow-up as they could indicate copied content or proxying of the legitimate Council on Foreign Relations website.

Figure 3. Dozens of IP addresses and a handful of domain names have used a &lt;meta&gt; tag that includes the Facebook App ID of the Council on Foreign Relations over the last year.

Figure 3. Dozens of IP addresses and a handful of domain names have used a <meta> tag that includes the Facebook App ID of the Council on Foreign Relations over the last year.

CSS Similarities

The CSS class hash 6971626bf83b92c4ceef538c8919ca17 indicates significant structural similarities between subdomains of the second decoy domain, dosportal[.]app, and the subdomains of the-washington-ballet[.]com. This pivot also exposes two possible origin IP addresses for these Cloudflare-fronted domains: 151.236.15[.]213 (AS 9009 - M247) and 185.158.250[.]155 (AS 212228 - servinga-UK).

Figure 4. Domains and IP addresses that returned HTML with CSS class similarities to the known decoy domain dosportal[.]app.

Figure 4. Domains and IP addresses that returned HTML with CSS class similarities to the known decoy domain dosportal[.]app.

Possible Evilginx

Between January 13, 2026 and February 2, 2026, several subdomains of stateaffairs[.]us returned host responses indicating a possible Evilginx configuration similar to the domains I studied in our previous write-up about Laundry Bear. These responses redirected visitors to official US Department of State websites for about two weeks.

Figure 5. Possible Evilginx-configured redirect to an official US Department of State domain name.

Figure 5. Possible Evilginx-configured redirect to an official US Department of State domain name.

Similarly, on December 24 and 25, several subdomains of the-washington-ballet[.]com returned host responses that indicate possible Evilginx configuration. This redirect sent visitors to the official event page of the legitimate Washington Ballet website.

Figure 6. Possible Evilginx-configured redirect to the events page of the real Washington Ballet from the lookalike domain, the-washington-ballet[.]com.

Figure 6. Possible Evilginx-configured redirect to the events page of the real Washington Ballet from the lookalike domain, the-washington-ballet[.]com.

UNC7005

GTIG notes that UNC7005 “shares many high-level similarities with UNC6293, including targeting overlaps” but tracks it separately due to its lower sophistication, poor operational security, divergent infrastructure characteristics, and the use of malware. In addition to Microsoft device code phishing, UNC7005 is reported to use device code phishing to target WhatsApp accounts.

Figure 7. WhatsApp device code phishing lure as captured by Validin.

Figure 7. WhatsApp device code phishing lure as captured by Validin.

my-invite[.]org

According to the GTIG report, the domain my-invite[.]org is an actor-controlled domain that facilitated phishing through links in email. The domain was only active for a few weeks beginning in late April and resolved to 104.194.159[.]150.

Figure 8. Validin’s Historical DNS timeline view for my-invite[.]org.

Figure 8. Validin’s Historical DNS timeline view for my-invite[.]org.

Historical DNS for 104.194.159[.]150 shows overlap with the related domain ms365-live[.]com, which provides numerous pivots to other domain clusters.

Figure 9. The timeline of DNS history shows infrastructure reuse in more recent campaigns.

Figure 9. The timeline of DNS history shows infrastructure reuse in more recent campaigns.

While my-invite[.]org resolved to 104.194.159[.]150, the fake invite page was updated around May 12th, 2026. In addition to the title changing from “Institute of Advanced Studies — Distinguished Lecture: AI, Law & the Future of Privacy” to “GLOBSEC — GLOBSEC Forum 2026 — 21st Edition”, the advertised location changed to “Prague Congress Centre, Prague, Czechia,” the deadline was updated to “12 May 2026,” and a new “regrets” email address was added: registration[@]globsec[.]org (note that globsec[.]org is a benign, unrelated domain).

Figure 10. The most recently extracted text before the domain my-invite[.]org stopped resolving to an IP address shows the approach of the lure.

Figure 10. The most recently extracted text before the domain my-invite[.]org stopped resolving to an IP address shows the approach of the lure.

statistic-ms[.]live

From March 18, 2026 until April 21, 2026, statistic-ms[.]live redirected to https[:]//ad-g[.]org/login, which displayed an “Ad Manager” login prompt until about August 5, 2026.

Figure 11. Screenshot of the login prompt at https[:]//ad-g[.]org/login.

Figure 11. Screenshot of the login prompt at https[:]//ad-g[.]org/login.

UNC5976

The domain drive[.]google[.]verify-drive[.]com was used in an OAuth phishing campaign. GTIG notes that numerous domains were created and deactivated in the following months but lists only this domain for the phishing activity cluster.

Figure 12. Validin captured a host response from that domain on March 11, 2026 with the title “My Drive - Google Drive”.

Figure 12. Validin captured a host response from that domain on March 11, 2026 with the title “My Drive - Google Drive”.

(Lack of) DNS Pivots

At first, the IP 93.127.160[.]28 (AS 47447 - TTM - 23 GmbH, Germany) looked promising as a pivot because it appeared to be a dedicated IP with relatively few associated domains. However, dozens of other domains point to that IP, and none began resolving there until about two months after verify-drive[.]com.

Figure 13. Historical DNS timeline shows a 2 month gap between verify-drive[.]com and other domain names.

Figure 13. Historical DNS timeline shows a 2 month gap between verify-drive[.]com and other domain names.

I compared the “Server:” header returned in host responses by opening the “Host Connections” tab and filtering for HOST-SERVER. In this view, I observed that the switch from “nginx/1.18.0 (Ubuntu)” to “Apache” happened right around the time that the other domains started resolving to 93.127.160[.]28. This suggests that the IP may have changed hands and that verify-drive[.]com may have been abandoned by the operator.

Figure 13. Progression of “Server” header values over time.

Figure 13. Progression of “Server” header values over time.

Title Pivots

The title “My Drive - Google Drive” is a potentially useful pivot, but it requires additional filtering because many domains with that title return very different responses and look nothing like the lure in the GTIG report.

Figure 14. A screenshot of a domain hosted on pages[.]dev captured by Validin’s live scanning tool shows a page with the title “My Drive - Google Drive” but a presentation that looks nothing like the original lure.

Figure 14. A screenshot of a domain hosted on pages[.]dev captured by Validin’s live scanning tool shows a page with the title “My Drive - Google Drive” but a presentation that looks nothing like the original lure.

To narrow the search, I applied a “Header Hash” filter to the title search, using the header hash returned by Validin’s capture of the lure: e4c0a20a5e50632867cd. This view revealed 26 domains and IPs that returned the combination of the title “My Drive - Google Drive” and used similar HTTP tooling stacks.

Figure 15. Title tag search with a header hash filter returns a distilled set of candidate domains.

Figure 15. Title tag search with a header hash filter returns a distilled set of candidate domains.

The following domains and IP addresses showed hosting and content similarities and were active between December 24, 2025 and March 17, 2026.

Domains with similar registration history
fllefolder[.]com
verify-drive[.]com
drive[.]google[.]verify-drive[.]com
sharefolders[.]org
drive[.]google[.]sharefolders[.]org
formshare[.]cloud
drive[.]google[.]formshare[.]cloud
sharedfolders[.]org
drive[.]google[.]sharedfolders[.]org
eurcpa[.]org
drive[.]google[.]anticorruption[.]eurcpa[.]org
sharedfolders[.]app
drive[.]google[.]sharedfolders[.]app
usercontent[.]app
drive[.]google[.]usercontent[.]app
usercontent[.]online
drive[.]google[.]usercontent[.]online

Virtual host responses that returned a certificate for another domain, suggesting incidental overlap (e.g., dangling DNS).

Domains with likely incidental overlap
export[.]galmabuna[.]com
www[.]hosting-backup[.]com
baranbo[.]shop
mail[.]baranbo[.]nl
www[.]010kerstbomen[.]nl
www[.]bouw-projecten[.]nl
bouw-bemiddeling[.]nl
forc[.]email
ukrspecsystens[.]com
IP addresses
138.226.240[.]37
93.127.160[.]28
187.77.12[.]131
187.77.168[.]166
89.116.64[.]250
153.92.222[.]46
72.62.187[.]155
185.223.57[.]126

Favicon Pivots

The response captured for drive[.]google[.]verify-drive[.]com returned a favicon with the MD5 hash c66f20f2e39eb2f6a0a4cdbe0d955e5f. Despite closely resembling the Google Drive logo, this favicon is distinct and has been captured by Validin on only 39 domains over the last year, many with just one or two measurements.

Figure 16. The favicon is a PNG and renders as the “Google Drive” logo.

Figure 16. The favicon is a PNG and renders as the “Google Drive” logo.

Using a filtering similar to the approach above, I distinguished responses that included a valid certificate from those without one. Because there is significant overlap with domains already identified, I included only the net-new domains.

Figure 17. Timeline of domains sharing the unique favicon hash c66f20f2e39eb2f6a0a4cdbe0d955e5f.

Figure 17. Timeline of domains sharing the unique favicon hash c66f20f2e39eb2f6a0a4cdbe0d955e5f.

Net-new domains with valid certificates and similar HTTP content
fileshareapp[.]org
Dissimilar HTTP content or certificates for another domain
# Dissimilar content:
drive[.]worksplace[.]cloud
antonov[.]live
login[.]antonov[.]live
account[.]securemail3d[.]ru
gdrive[.]gregc[.]online
mail2[.]spravedlivo[.]site
accounts[.]gsecure[.]space (Redirected to accounts[.]google[.]com)
login[.]intergroup[.]media
cyzz[.]pages[.]dev
drive[.]google[.]anticens[.]xyz
hamburger-c33[.]pages[.]dev
schoolclasssciencemath[.]me

# Invalid certificate:
www[.]xn--80abhgqfmrcigxgke9b9f[.]xn--p1ai ("www[.]бесплатныйхостинг[.]рф")
cloud[.]mailsecure[.]ru
cloud[.]3dsecurity[.]ru
8291[.]ru
portal[.]spravedlivo[.]site
cloud[.]rsecure[.]ru
portal[.]owalogin[.]ru

Registration Similarities

UNC6293 had a small cluster of domains that were registered around the same time. Using Validin’s “Quick Pivots” suggestion on the “Registration” tab, I initiated an advanced search for domain names registered within five minutes of the target domain and sharing the same registrar and name servers.

Figure 18. How to initiate a “similar registration” search in two clicks.

Figure 18. How to initiate a “similar registration” search in two clicks.

This generated the following search query:

Net-new domains with valid certificates and similar HTTP content
registration: (registrar = "OwnRegistrar, Inc." AND registered = "2026-03-02T07:26:52Z~5m" AND ns = "5545.dns1.managedns.org" AND ns = "5545.dns2.managedns.org" AND ns = "5545.dns3.managedns.org" AND ns = "5545.dns4.managedns.org")
Figure 19. Advanced search results for similar registrations to verify-drive[.]com.

Figure 19. Advanced search results for similar registrations to verify-drive[.]com.

These domains are not necessarily related, but they provide a narrow starting point for verification.

Domains with similar registration history
supportnoreplay[.]com
security-forms[.]com
noreplaysupport[.]com
info-forms[.]com

Ghost Domain?

Interestingly, supportnoreplay[.]com is NX despite being registered through OwnRegistrar, Inc. on March 2, 2026, at 07:26:46 UTC. It has also remained NX, without even a name server response, since at least September 9, 2021.

Figure 20. The domain supportnoreplay[.]com hasn’t returned any DNS records, not even name servers, for years. It was registered most recently on March 2, 2026.

Figure 20. The domain supportnoreplay[.]com hasn’t returned any DNS records, not even name servers, for years. It was registered most recently on March 2, 2026.

While I couldn’t confirm that these domains are related, their “security”, “support”, and “form” themes provide a reasonable basis for monitoring their future use.

Conclusion

Validin has historical DNS, host response data, header hashes, favicons, certificates, and registration records that help identify infrastructure related to known indicators. While the findings in this report are not exhaustive, these examples show how multiple pivot techniques can surface additional domains and infrastructure associated with Russian cyber espionage activity. These techniques can be applied to many other types of threat hunts.

By combining point-in-time indicators from GTIG’s reporting with Validin’s historical and proactive scanning data, analysts can expand infrastructure clusters, evaluate potential relationships, and continue tracking activity as infrastructure changes over time.

Indicators

Only net-new indicators suspected to be related to the campaigns discussed above are listed below.

UNC6293
internationalaffairsportal[.]us
stateaffairs[.]us
the-washington-ballet[.]com

# Possible origin IPs
151.236.15[.]213
185.158.250[.]155
UNC7005
ad-g[.]org
UNC5976
fllefolder[.]com
sharefolders[.]org
drive[.]google[.]sharefolders[.]org
formshare[.]cloud
drive[.]google[.]formshare[.]cloud
sharedfolders[.]org
drive[.]google[.]sharedfolders[.]org
eurcpa[.]org
drive[.]google[.]anticorruption[.]eurcpa[.]org
sharedfolders[.]app
drive[.]google[.]sharedfolders[.]app
usercontent[.]app
drive[.]google[.]usercontent[.]app
usercontent[.]online
drive[.]google[.]usercontent[.]online
fileshareapp[.]org
linkfileshare[.]net (identified via registration pivot)
drive[.]google[.]linkfileshare[.]net (identified via registration pivot)

# Low confidence registration pivots:
supportnoreplay[.]com
security-forms[.]com
noreplaysupport[.]com
info-forms[.]com
Share this Post

Get in touch

Contact us

Validin is the first tab I open every morning.
Senior Analyst, Financial Services IT Company