How Russian Hackers Bypassed Gmail 2FA Using App Passwords – APT29’s Targeted Email Attack Explained

In a highly targeted campaign, Russian APT group APT29 tricked victims into creating Google App Passwords, allowing hackers to bypass Gmail’s 2FA security and gain long-term access to emails. Learn how this cyberattack unfolded, the dangers of app passwords, and expert tips to secure your account in 2026.

Jun 23, 2025 - 10:26
105.2k
How Russian Hackers Bypassed Gmail 2FA Using App Passwords – APT29’s Targeted Email Attack Explained

Table of Contents

What Happened?

Between April and June 2025, a Russian-linked hacking group known as APT29 (also called Cozy Bear or Midnight Blizzard) used a clever trick to bypass Gmail's two-factor authentication (2FA). They did this by convincing victims—usually high-profile critics of Russia or academics—to create Google App Passwords, giving hackers permanent access to email accounts.

This wasn’t a fast attack. Instead, it involved slow, carefully crafted social engineering to earn trust, manipulate victims, and quietly steal access—all while avoiding detection.

 Background: Who Is APT29?

APT29 is a Russian state-sponsored Advanced Persistent Threat group, believed to be linked to the Russian Foreign Intelligence Service (SVR). They've been behind many cyber-espionage operations including attacks on the US government, NATO, and research institutions. Their tactics involve stealth, persistence, and clever use of social engineering.

 How the Attack Worked: Step-by-Step

Phase Action by APT29
Phase 1 Identified targets: mostly critics of Russia or academics
Phase 2 Initiated contact through fake "@state.gov" emails
Phase 3 Sent fake meeting invitations to appear authentic
Phase 4 Built trust over weeks using conversation and credibility
Phase 5 Requested victims to set up a Google App Password
Phase 6 Received the password and used it to access emails via a mail client

 What Are App Passwords?

Google App Passwords are 16-character codes that let apps or devices access a Google account without needing a 2FA code. They’re usually meant for older applications that can’t support modern security features.

APT29 used this loophole by convincing users to generate and share this code, which completely bypassed two-factor authentication.

What Made This Attack So Effective?

  • No urgency or threats – unlike typical phishing.

  • Realistic email headers – four fake but believable "@state.gov" addresses in CC.

  • PDF instructions – guiding victims step-by-step to create the app password.

  • Fake secure environment – tricked users into thinking they were joining an official Department of State system.

  • Persistent Access – once in, attackers could keep reading emails without raising alarms.

 What Is Device Join Phishing?

APT29 is also using Device Join Phishing, a newer trick. Here's how it works:

  • The hacker sends a meeting invite with a legitimate Microsoft link.

  • The user clicks and unknowingly gives the attacker a valid OAuth device code.

  • The attacker uses it to register a new device with the victim’s account.

  • Boom—persistent access granted, again bypassing traditional security.

 Expert Insights

  • Citizen Lab confirmed that State Department servers don’t reject non-existent emails, making fakes harder to detect.

  • Google’s Threat Intelligence Group calls this campaign “one of the most personalized phishing efforts ever seen.”

  • Microsoft and Google have both issued alerts about rising abuse of OAuth and app-based permissions.

 How to Protect Yourself

✅ 1. Don’t share app passwords

Never generate or share app passwords unless you fully trust the application and source.

✅ 2. Monitor account activity

Check for unknown devices or logins via Google’s security settings.

✅ 3. Use app password alerts

Enable account alerts for new logins or app password usage.

✅ 4. Avoid PDF-based instructions

If a stranger sends PDF steps asking you to change your account settings—be cautious.

✅ 5. Review third-party apps

Visit your Google/Microsoft security dashboard to review permissions granted to apps.

 Real-World Impact

This campaign was not random spam—it was targeted espionage. The victims were selected carefully, and the operation involved:

  • 500 GitHub repositories

  • Thousands of Pastebin views

  • Access to Gmail, Discord, Telegram, VPNs, and crypto wallets

APT29 adapted to avoid detection, using VPNs and residential proxies to log in without triggering alerts.

Conclusion

The Russian group APT29 used app passwords and advanced social engineering to bypass Gmail 2FA and gain access to high-value email accounts. The attack was subtle, professional, and persistent—showing that traditional security is no longer enough. It's a clear reminder that even “secure” systems can be bypassed when trust is manipulated.

FAQs

APT29, also known as Cozy Bear or Midnight Blizzard, is a Russian state-sponsored hacker group involved in cyber-espionage campaigns.

They convinced users to generate Google App Passwords, which bypass standard 2FA protections when used in third-party email clients.

App Passwords are 16-character codes that let less secure apps access a Gmail account without triggering 2FA.

Once generated, they provide full access to email without needing the main password or 2FA, making them vulnerable if misused.

2FA stands for Two-Factor Authentication, a security measure that requires both a password and a second verification step.

Prominent academics, government critics, and individuals connected to U.S. and Ukrainian affairs were targeted.

They used spoofed email addresses pretending to be from the U.S. State Department.

UNC6293 is the code name used by Google’s Threat Intelligence Group to identify this specific threat campaign.

The attackers slowly built trust over emails before tricking users into generating app passwords.

Phishing is a fraudulent attempt to obtain sensitive information by pretending to be a trustworthy source.

Because app passwords bypass the need for Gmail’s 2FA and don’t trigger the same security warnings.

Besides Gmail, the attackers also tried to access Discord, Telegram, and possibly Microsoft 365.

It’s a phishing technique that tricks users into authorizing a new device via OAuth, granting attackers access.

Google reports the campaign was active from April to June 2025 but may continue in modified forms.

They used VPNs and residential proxies to log in from common IP ranges, avoiding geolocation alerts.

GTIG is a cybersecurity division within Google that investigates and reports on advanced cyber threats.

Check your Gmail account activity, remove app passwords, and review third-party access permissions immediately.

No. This attack relies on social engineering, not malware, so antivirus tools often miss it.

Use a hardware key or Google Authenticator instead of relying on SMS or app passwords.

They spoof sender addresses and use fake email chains to appear as internal government communication.

The PDF guided victims step-by-step to generate and share their app password.

Yes, by turning off "Less secure app access" or removing existing app passwords from your Google Account settings.

App passwords were created to help older apps that don’t support modern login flows access Gmail.

Yes, Microsoft has also reported similar OAuth-based phishing attempts by Russian threat actors.

It tricks victims into giving permission to third-party apps that attackers control.

Cozy Bear has been linked to numerous high-profile hacks including those of U.S. federal agencies.

They reportedly maintained access to inboxes over several weeks once app passwords were set up.

Yes, especially if individual employees fall victim to phishing or misuse authentication tools.

Use modern apps that support OAuth, monitor account activity, and train users to recognize phishing.

Microsoft identified a parallel phishing campaign targeting Microsoft 365 accounts using OAuth exploits.

Yes, if users fall for similar phishing emails or share their app passwords with attackers.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.