logo

Russian hackers bypass Gmail MFA using stolen app passwords

ID: 1aaa94d9-5e9b-58c6-884c-c553e8960787

STIX ID: report--1aaa94d9-5e9b-58c6-884c-c553e8960787

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-06-21

Date Updated: 2026-04-20

Author: Ionut Ilascu

...
...

UNC6293 — a Russian-linked threat actor likely associated with APT29 — executed a slow, highly personalized spearphishing campaign targeting academics and critics of Russia by impersonating U.S. State Department officials and convincing victims to create and share Google app-specific passwords, thereby bypassing MFA and granting full access to Gmail accounts; investigators from Google Threat Intelligence Group and The Citizen Lab observed fake identities, instructional PDFs, residential proxies/VPS infrastructure, and recommend increased protections such as Google's Advanced Protection Program.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.