Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Suspected Russian-linked threat actors are using social engineering tactics to impersonate the U.S. Department of State and gain access to victims’ emails through application-specific passwords. Google and Microsoft have identified campaigns involving spear-phishing and fake meeting invitations to establish persistent access for espionage activities. #UNC6293 #APT29

Keypoints

  • Threat actors target high-profile individuals using tailored social engineering methods.
  • Attackers impersonate the U.S. Department of State through sophisticated phishing campaigns.
  • Application-specific passwords are exploited to bypass two-factor authentication and maintain access.
  • Malicious campaigns involve fake meeting invitations with credible-looking email addresses.
  • OTargeted campaigns include techniques like device code phishing and OAuth token hijacking.

Read More: https://thehackernews.com/2025/06/russian-apt29-exploits-gmail-app.html