Risky Bulletin Newsletter
June 20, 2025
Risky Bulletin: Russian hackers abuse app-specific passwords to bypass MFA
Presented by

News Editor
Russian cyber-spies have developed a new social engineering technique designed to extract application-specific passwords from their targets.
Also known as app passwords, or ASPs, these allow attackers to bypass multi-factor authentication and access a victim's Gmail accounts.
App passwords are supported on multiple online platforms, but this campaign specifically targeted Google's ASPs. These are 16-character codes that users manually generate from their Google account security page. They can be copy-pasted inside older apps that don't support Google's more modern 2FA/MFA authentication procedures.