APT29 — APT Profile
APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015. In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard, G0016, ATK7, Cloaked Ursa, TA421, ITG11, BlueBravo, UAC-0029, ICECAP, ICE RELIC, StellarParticle, Solar Phoenix
IntelFusions coverage (9)
- Spies and ransomware crews exploit the same edge devices 2026-08-26 · Vulnerabilities
- Russia's spies phish by asking you to link your WhatsApp 2026-08-20 · Nation-State
- Russian hackers hijack hotel Wi-Fi to bug travelers 2026-08-01 · Nation-State
- Attackers hijack Microsoft 365 accounts using Microsoft's own login page 2026-07-06 · Cyber Incidents
- Phishing service steals Microsoft 365 logins and survives MFA 2026-07-01 · Cyber Incidents
- Hackers are phishing employees through Microsoft Teams, not email 2026-06-10 · Nation-State
- Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication 2026-02-16 · Nation-State
- Gamaredon Group: Russia's Most Prolific APT Against Ukraine, Powered by Custom Malware and SFX Persistence 2026-02-16 · Nation-State
- The Enigmatic Energetic Bear: Russia's Most Successful Critical Infrastructure Intruder You've Never Heard Of 2026-02-16 · Nation-State
Tools & malware
- AADInternals Credential Harvesting
- AdFind Network Reconnaissance
- apk.androsnatch Mobile Malware
- apk.unidentified_009 Mobile Malware
- BloodHound Network Reconnaissance
- BoomBox Downloader
- CloudDuke Backdoor
- Cobalt Strike Adversary Simulation
- CosmicDuke Backdoor
- CozyCar Backdoor
- EnvyScout Downloader
- FatDuke Backdoor
- FoggyWeb Backdoor
- GeminiDuke Backdoor
- GoldFinder Backdoor
- GoldMax Backdoor
- HAMMERTOSS Backdoor
- Impacket Network Toolkit
- ios.cookiesnatch Mobile Malware
- ios.validvictor Mobile Malware
- ipconfig Network Reconnaissance
- LiteDuke Backdoor
- meek Tunneling Tool
- Mimikatz Credential Harvesting
- MiniDuke Backdoor
- NativeZone Loader
- Net Network Reconnaissance
- OnionDuke Backdoor
- PinchDuke Backdoor
- PolyglotDuke Backdoor
- POSHSPY Backdoor
- PowerDuke Backdoor
- PsExec Remote Execution
- QUIETEXIT Backdoor
- Raindrop Loader
- RegDuke Backdoor
- reGeorg Tunneling Tool
- ROADTools Credential Harvesting
- SDelete Defense Evasion
- SeaDuke Backdoor
- Sibot Downloader
- Sliver Adversary Simulation
- SoreFang Backdoor
- SUNBURST Backdoor
- SUNSPOT Implant
- Systeminfo Discovery
- Tasklist Discovery
- TEARDROP Loader
- Tor Anonymization Tool
- TrailBlazer Backdoor
- VaporRage Downloader
- WellMail Backdoor
- WellMess Backdoor
- win.beatdrop Backdoor
- win.boombox Backdoor
- win.cloud_duke Backdoor
- win.cobalt_strike Adversary Simulation
- win.cosmicduke Backdoor
- win.cozyduke Backdoor
- win.fatduke Backdoor
Vendor research
- UNC3524: Eye Spy on Your Email Mandiant
- IRON HEMLOCK Secureworks CTU
- Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign Dunwoody, M., et al
- Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor FireEye
- Microsoft Threat Intelligence Microsoft
- IRON RITUAL Secureworks CTU
- How Microsoft names threat actors Microsoft
- Analysis of cyberattack on U.S. think tanks, non-profits, public sector by unidentified attackers Microsoft Defender Research Team
- Imposing Costs for Harmful Foreign Activities by the Russian Government White House
- New Nobelium activity MSRC
- Breaking down NOBELIUM’s latest early-stage toolset MSTIC
- GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence MSTIC
- Advisory: APT29 targets COVID-19 vaccine development NCSC
- Further TTPs associated with SVR cyber actors Cybersecurity Advisory SVR TTP
- Russian SVR Targets U.S. and Allied Networks NSA
- WellMess malware: analysis of its Command and Control (C2) server PWC
- How WellMess malware has been used to target COVID-19 vaccines PWC
- Secureworks CTU. (n.d.). IRON HEMLOCK Secureworks
- Secureworks CTU. (n.d.). IRON RITUAL Secureworks
- UK and US expose global campaign of malign activity by Russian intelligence services UK GOV
- UK exposes Russian involvement in SolarWinds cyber compromise UK GOV
- UK and US call out Russia for SolarWinds compromise UK NSCS Russia SolarWinds
- SolarStorm Supply Chain Attack Timeline Unit 42
- Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign FireEye
- Imposing Costs for Harmful Foreign Activities by the Russian Government White House