ThreatBox · Threat Actor Attribution
APT29
a.k.a. Cozy Bear, Nobelium, The Dukes, Midnight Blizzard
Espionage (state-sponsored) Russia (SVR) First seen 2008
APT29 is one of Russia's most sophisticated state-sponsored espionage groups, attributed to the Foreign Intelligence Service (SVR). Known for stealth, custom malware, and supply-chain attacks (SolarWinds SUNBURST, 2020). Long dwell times and living-off-the-land techniques make detection difficult.
Targeted sectors
GovernmentDiplomatic missionsThink tanksHealthcare (COVID-19 research)
Targeted regions
NATO countriesEUUSA
Known TTPs (5)
T1195.002Compromise Software Supply Chain
T1078.004Valid Cloud Accounts
T1059.001PowerShell
T1027Obfuscated Files or Information
T1105Ingress Tool Transfer
Click any technique to open the MITRE ATT&CK reference.
Attack Timeline
- 2015-07Democratic National Committee breach
- 2020-03SolarWinds SUNBURST supply-chain attack begins
- 2020-12SolarWinds compromise publicly disclosed
- 2023-11Microsoft Midnight Blizzard corporate breach
References
End of dossier · APT29
Back to ThreatBox