
Russian-linked threat actors are using a clever new social engineering technique to steal email access by exploiting Google’s application-specific password feature, according to recent findings from Google Threat Intelligence Group and Citizen Lab.
## The Attack Campaign
From April through early June 2025, hackers targeted prominent academics and Russian critics using an elaborate impersonation scheme. The attackers posed as U.S. Department of State officials to trick victims into creating and sharing Google app passwords—16-digit codes that provide direct access to email accounts.
Google attributes this activity to UNC6293, a threat group likely connected to APT29, the notorious Russian state-sponsored hacking organization also known as Cozy Bear or Midnight Blizzard.
## How the Scam Works
Unlike typical phishing attacks that create urgency, this campaign unfolds over several weeks to build trust with targets:
1. **Initial Contact**: Attackers send seemingly legitimate meeting invitations with fake “@state.gov” email addresses in the CC line to appear credible
2. **Building Trust**: Multiple benign emails establish rapport without raising suspicion
3. **The Hook**: Victims receive a PDF with step-by-step instructions to create an app password for “secure communications”
4. **Access Granted**: Once victims share the 16-digit code, hackers gain persistent access to their email accounts
## Technical Exploitation
Google app passwords are designed to help less secure applications access accounts with two-factor authentication enabled. However, attackers are weaponizing this legitimate security feature by convincing victims they need these passwords to access a fake Department of State cloud environment.
The hackers then use residential proxies and VPS servers to access compromised accounts while avoiding detection.
## Broader Pattern
This campaign represents part of a larger trend of sophisticated Russian cyber operations. Microsoft has observed similar attacks since April 2025, where threat actors use device code phishing and device join phishing techniques to compromise Microsoft 365 accounts.
## Response and Protection
Google has secured the compromised accounts and continues monitoring these threats. The company also identified a second campaign with Ukrainian themes using similar tactics.
This attack highlights the evolving nature of social engineering, where patience and relationship-building replace traditional high-pressure tactics to bypass security measures and human intuition.
