216.73.216.6

What's in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia

· Published 18/06/2025 23:37 · Modified 23/06/2025 20:11

Export JSON

Essential information

Published
18/06/2025 23:37
Modified
23/06/2025 20:11
Tags
2025-06-18 asp department of state email compromise phishing state-sponsored
Related entities
2 observables, 1 intrusion sets (apt), 9 techniques (mitre), 2 others

Description

A Russia cyber threat actor impersonated the U.S. to target prominent academics and critics of Russia. The attackers used extensive rapport building and tailored lures to convince targets to set up application specific passwords (ASPs). Once obtained, these ASPs allowed persistent access to victims' mailboxes. Two distinct campaigns were observed, both using residential proxies and VPS servers for access. The attackers sent emails disguised as meeting invitations, including spoofed email addresses to increase legitimacy. Victims were directed to create ASPs with specific names, which the attackers then used to access their email accounts. This activity is tracked as UNC6293 and is assessed with low confidence to be associated with APT29 / ICECAP.

External references