A group of professional Russian hackers linked to the government has been spotted using a new, slow but effective phishing technique that bypasses MFA authentication by exploiting Google's lesser-known " app-specific passwords " feature
See also: Russian hackers target Tajik government

According to documentation from Threat Intelligence Group , the operation ran from April to early June and involved sending emails pretending to come from US State Department officials, in perfect English, embedded in authentic emails and shared with four fake recipients with @state.gov.
Google is tracking a group of Russian hackers called UNC6293 and believes it is linked to APT29, the Russian intelligence blamed for the 2016 attack on the Democratic National Committee. Researchers estimate that the group spent weeks approaching each target before sending detailed instructions on how to use the ASP (application-specific password) feature.
One of the victims, British writer Keir Giles of Chatham House, exchanged more than a dozen emails with a sender who identified himself as “Claudie S. Weber.” The messages were sent during business hours in Washington and used email addresses that did not return an error.
See also: Russian APT28 targets organizations supporting Ukraine
After trust was built through communication, Google said the scammer sent a six-page PDF file, with a fake U.S. State Department letterhead, instructing the victim to visit their Google account settings page, create a 16-digit password called “ms.state.gov,” and email it back “to complete secure activation.”

With this code, the Russian hackers gained persistent access to the target's Gmail account, without the need for two-factor verification (MFA).
Citizen Lab, which reviewed the deceptive material at Giles' request, noted that the emails and PDF did not contain the usual linguistic errors found in phishing attacks. Researchers suspect that artificial intelligence tools were used for linguistic editing and evasion.
Google linked Giles's incident to a second wave focusing on Ukrainian issues. And in both cases, the intruders routed the connections through the same home IP proxy and occasionally reused the node on different victims.
See also: France: Blames Russian hackers APT28 for attacks on the country
The incident described is a prime example of the increasing sophistication and “surgical precision” of cyberattacks, especially when linked to state actors or well-resourced organized groups such as APT29. The most worrying element is the use of artificial intelligence tools to create completely convincing content, without the familiar linguistic errors that usually give away phishing attacks. This means that even well-informed and careful users can be fooled.
Source: securityweek
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
