Back to ThreatBox
ThreatBox · Threat Actor Attribution

APT29

a.k.a. Cozy Bear, Nobelium, The Dukes, Midnight Blizzard
Espionage (state-sponsored) Russia (SVR) First seen 2008

APT29 is one of Russia's most sophisticated state-sponsored espionage groups, attributed to the Foreign Intelligence Service (SVR). Known for stealth, custom malware, and supply-chain attacks (SolarWinds SUNBURST, 2020). Long dwell times and living-off-the-land techniques make detection difficult.

Targeted sectors
GovernmentDiplomatic missionsThink tanksHealthcare (COVID-19 research)
Targeted regions
NATO countriesEUUSA

Known TTPs (5)

Click any technique to open the MITRE ATT&CK reference.

Attack Timeline

  1. 2015-07
    Democratic National Committee breach
  2. 2020-03
    SolarWinds SUNBURST supply-chain attack begins
  3. 2020-12
    SolarWinds compromise publicly disclosed
  4. 2023-11
    Microsoft Midnight Blizzard corporate breach

References

End of dossier · APT29
Back to ThreatBox

Made with Emergent