UNC6293
- Origin
- RU
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:22:33
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:ua country_code:us
Context
UNC6293 is a Russian state-sponsored threat actor identified by Google's Threat Intelligence Group (GTIG), which associates them with APT29 with low confidence. They have conducted campaigns utilizing social engineering tactics, including leveraging App-Specific Passwords for account compromises. GTIG has also noted a second campaign by UNC6293 that incorporates Ukrainian themes.
Reports & references
- cloud.google.com — Creative Phishing Academics Critics Of Russia (report)