Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Application specific passwords, also known as app passwords, are a Google account feature that threat actors with suspected Russian connections have been seen using as part of a new social engineering technique to access victims’ emails.

Google Threat Intelligence Group (GTIG) and Citizen Lab revealed details of the highly targeted campaign, claiming that the activity aims to mimic the U.S. Department of State.

According to GTIG experts Gabby Roncone and Wesley Shields, this actor targeted well-known academics and Russian critics from at least April to early June 2025. They frequently used a lot of rapport-building and specially designed lures to persuade the target to create application-specific passwords (ASPs).

The attackers have continuous access to the victim’s email when the target divulges the ASP passcode read more about Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *