Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
Russian-linked cyber espionage operators are expanding account-compromise operations by combining OAuth abuse, device-code phishing, credential-harvesting infrastructure, and suspected Evilginx reverse-proxy setups. GTIG assesses with moderate confidence …