logo

Same Sea, New Phish: Russian Government-Linked Social Engineering Targets App-Specific Passwords

ID: 7a22136b-bbac-5fa4-9502-eab43dc616d5

STIX ID: report--7a22136b-bbac-5fa4-9502-eab43dc616d5

Feed Name: The Citizen Lab

Threat Score
75/100

Date Published: 2025-06-18

Date Updated: 2026-04-19

Author: John Scott-Railton

...
...

Citizen Lab documents a sophisticated, targeted social-engineering campaign that convinced expert Keir Giles to create and share App-Specific Passwords (ASPs), enabling account compromise. Google linked the operation to UNC6293 (low-confidence to APT29), blocked the attacker, and the report highlights ASP-focused social engineering as an emerging TTP with provided indicators and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.