APT29 — APT Profile
APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015. In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.Also tracked as
IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard
Tools & malware
- AADInternals Credential Harvesting
- AdFind Network Reconnaissance
- apk.androsnatch Mobile Malware
- apk.unidentified_009 Mobile Malware
- BloodHound Network Reconnaissance
- BoomBox Downloader
- CloudDuke Backdoor
- Cobalt Strike Adversary Simulation
- CosmicDuke Backdoor
- CozyCar Backdoor
- EnvyScout Downloader
- FatDuke Backdoor
- FoggyWeb Backdoor
- GeminiDuke Backdoor
- GoldFinder Backdoor
- GoldMax Backdoor
- HAMMERTOSS Backdoor
- Impacket Network Toolkit
- ios.cookiesnatch Mobile Malware
- ios.validvictor Mobile Malware
- ipconfig Network Reconnaissance
- LiteDuke Backdoor
- meek Tunneling Tool
- Mimikatz Credential Harvesting
- MiniDuke Backdoor
- NativeZone Loader
- Net Network Reconnaissance
- OnionDuke Backdoor
- PinchDuke Backdoor
- PolyglotDuke Backdoor
- POSHSPY Backdoor
- PowerDuke Backdoor
- PsExec Remote Execution
- QUIETEXIT Backdoor
- Raindrop Loader
- RegDuke Backdoor
- reGeorg Tunneling Tool
- ROADTools Credential Harvesting
- SDelete Defense Evasion
- SeaDuke Backdoor
- Sibot Downloader
- Sliver Adversary Simulation
- SoreFang Backdoor
- SUNBURST Backdoor
- SUNSPOT Implant
- Systeminfo Discovery
- Tasklist Discovery
- TEARDROP Loader
- Tor Anonymization Tool
- TrailBlazer Backdoor
- VaporRage Downloader
- WellMail Backdoor
- WellMess Backdoor
- win.beatdrop Backdoor
- win.boombox Backdoor
- win.cloud_duke Backdoor
- win.cobalt_strike Adversary Simulation
- win.cosmicduke Backdoor
- win.cozyduke Backdoor
- win.fatduke Backdoor
Vendor research
- Analysis of cyberattack on U.S. think tanks, non-profits, public sector by unidentified attackers Microsoft Defender Research Team
- IRON HEMLOCK Secureworks CTU
- IRON RITUAL Secureworks CTU
- Imposing Costs for Harmful Foreign Activities by the Russian Government White House
- How Microsoft names threat actors Microsoft
- Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign FireEye
- The Dukes: 7 years of Russian cyberespionage F-Secure The Dukes
- OPERATION GHOST ESET
- Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor FireEye
- NobleBaron | New Poisoned Installers Could Be Used In Supply Chain Attacks SentinelOne
- UNC3524: Eye Spy on Your Email Mandiant
- New sophisticated email-based attack from NOBELIUM MSTIC
- New Nobelium activity MSRC
- Breaking down NOBELIUM’s latest early-stage toolset MSTIC
- GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence MSTIC
- Advisory: APT29 targets COVID-19 vaccine development NCSC
- Further TTPs associated with SVR cyber actors Cybersecurity Advisory SVR TTP
- Russian SVR Targets U.S. and Allied Networks NSA
- WellMess malware: analysis of its Command and Control (C2) server PWC
- How WellMess malware has been used to target COVID-19 vaccines PWC
- Secureworks CTU. (n.d.). IRON HEMLOCK Secureworks
- Secureworks CTU. (n.d.). IRON RITUAL Secureworks
- UK and US expose global campaign of malign activity by Russian intelligence services UK GOV
- UK exposes Russian involvement in SolarWinds cyber compromise UK GOV
- UK and US call out Russia for SolarWinds compromise UK NSCS Russia SolarWinds