Russian hackers bypass Gmail MFA using stolen app passwords
ID: 1aaa94d9-5e9b-58c6-884c-c553e8960787
STIX ID: report--1aaa94d9-5e9b-58c6-884c-c553e8960787
Feed Name: Bleeping Computer
UNC6293 — a Russian-linked threat actor likely associated with APT29 — executed a slow, highly personalized spearphishing campaign targeting academics and critics of Russia by impersonating U.S. State Department officials and convincing victims to create and share Google app-specific passwords, thereby bypassing MFA and granting full access to Gmail accounts; investigators from Google Threat Intelligence Group and The Citizen Lab observed fake identities, instructional PDFs, residential proxies/VPS infrastructure, and recommend increased protections such as Google's Advanced Protection Program.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
