What's in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia

June 23, 2025, 8:11 p.m.

Description

A Russia state-sponsored cyber threat actor impersonated the U.S. Department of State to target prominent academics and critics of Russia. The attackers used extensive rapport building and tailored lures to convince targets to set up application specific passwords (ASPs). Once obtained, these ASPs allowed persistent access to victims' mailboxes. Two distinct campaigns were observed, both using residential proxies and VPS servers for access. The attackers sent phishing emails disguised as meeting invitations, including spoofed Department of State email addresses to increase legitimacy. Victims were directed to create ASPs with specific names, which the attackers then used to access their email accounts. This activity is tracked as UNC6293 and is assessed with low confidence to be associated with APT29 / ICECAP.

Date

  • Created: June 18, 2025, 11:37 p.m.
  • Published: June 18, 2025, 11:37 p.m.
  • Modified: June 23, 2025, 8:11 p.m.

Indicators

  • 329fda9939930e504f47d30834d769b30ebeaced7d73f3c1aadd0e48320d6b39
  • 91.190.191.117

Attack Patterns

Additional Informations

  • Government
  • United States of America