Threat actor
APT29
Last fetched
APT29 is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 66 techniques and also known as 29 other names.
Also known as
Group 100, COZY BEAR, The Dukes, Minidionis, SeaDuke, YTTRIUM, IRON HEMLOCK, Grizzly Steppe, G0016, ATK7, Cloaked Ursa, TA421, Blue Kitsune, ITG11, BlueBravo, Nobelium, UAC-0029, ICECAP, ICE RELIC, IRON RITUAL, NobleBaron, Dark Halo, NOBELIUM, UNC2452, Cozy Bear, CozyDuke, SolarStorm, UNC3524, Midnight Blizzard
Description
[APT29](https://attack.mitre.org/groups/G0016) is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).(Citation: White House Imposing Costs RU Gov April 2021)(Citation: UK Gov Malign RIS Activity April 2021) They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. [APT29](https://attack.mitre.org/groups/G0016) reportedly compromised the Democratic National Committee starting in the summer of 2015.(Citation: F-Secure The Dukes)(Citation: GRIZZLY STEPPE JAR)(Citation: Crowdstrike DNC June 2016)(Citation: UK Gov UK Exposes Russia SolarWinds April 2021) In April 2021, the US and UK governments attributed the [SolarWinds Compromise](https://attack.mitre.org/campaigns/C0024) to the SVR; public statements included citations to [APT29](https://attack.mitre.org/groups/G0016), Cozy Bear, and The Dukes.(Citation: NSA Joint Advisory SVR SolarWinds April 2021)(Citation: UK NSCS Russia SolarWinds April 2021) Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.(Citation: FireEye SUNBURST Backdoor December 2020)(Citation: MSTIC NOBELIUM Mar 2021)(Citation: CrowdStrike SUNSPOT Implant January 2021)(Citation: Volexity SolarWinds)(Citation: Cybersecurity Advisory SVR TTP May 2021)(Citation: Unit 42 SolarStorm December 2020)
Techniques by tactic
Persistence
- T1037 · Boot or Logon Initialization Scripts
- T1037.004 · RC Scripts
- T1053.005 · Scheduled Task
- T1078 · Valid Accounts
- T1078.003 · Local Accounts
- T1078.004 · Cloud Accounts
- T1098.002 · Additional Email Delegate Permissions
- T1098.005 · Device Registration
- T1133 · External Remote Services
- T1136.003 · Cloud Account
- T1505.003 · Web Shell
- T1546.003 · Windows Management Instrumentation Event Subscription
- T1546.008 · Accessibility Features
- T1547.001 · Registry Run Keys / Startup Folder
- T1556.007 · Hybrid Identity
Privilege Escalation
- T1037 · Boot or Logon Initialization Scripts
- T1037.004 · RC Scripts
- T1053.005 · Scheduled Task
- T1068 · Exploitation for Privilege Escalation
- T1078 · Valid Accounts
- T1078.003 · Local Accounts
- T1078.004 · Cloud Accounts
- T1098.002 · Additional Email Delegate Permissions
- T1098.005 · Device Registration
- T1546.003 · Windows Management Instrumentation Event Subscription
- T1546.008 · Accessibility Features
- T1547.001 · Registry Run Keys / Startup Folder
- T1548.002 · Bypass User Account Control
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to APT29 today — this states the absence of a published link, not that APT29 has no infrastructure.
References
- https://labsblog.f-secure.com/2015/09/17/the-dukes-7-years-of-russian-cyber-espionage/
- https://www2.fireeye.com/rs/848-DID-242/images/rpt-apt29-hammertoss.pdf
- https://www.us-cert.gov/sites/default/files/publications/AR-17-20045_Enhanced_Analysis_of_GRIZZLY_STEPPE_Activity.pdf
- https://www.fireeye.com/blog/threat-research/2017/03/dissecting_one_ofap.html
- https://www.cfr.org/interactive/cyber-operations/dukes
- https://pylos.co/2018/11/18/cozybear-in-from-the-cold/
- https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/analysis-of-cyberattack-on-u-s-think-tanks-non-profits-public-sector-by-unidentified-attackers/
- https://www.secureworks.com/research/threat-profiles/iron-hemlock
- https://attack.mitre.org/groups/G0016
- https://unit42.paloaltonetworks.com/atoms/cloaked-ursa/
- https://go.recordedfuture.com/hubfs/reports/cta-2023-0127.pdf
- https://cip.gov.ua/services/cm/api/attachment/download?id=60068
- https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/
- https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/
- https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/
- https://www.crowdstrike.com/blog/sunspot-malware-technical-analysis/
- https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/
- https://www.us-cert.gov/sites/default/files/publications/JAR_16-20296A_GRIZZLY%20STEPPE-2016-1229.pdf
- https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy-an-uncomfortable-examination-of-a-suspected-apt29-phishing-campaign.html
- https://www.f-secure.com/documents/996508/1030745/dukes_whitepaper.pdf
- https://www.welivesecurity.com/wp-content/uploads/2019/10/ESET_Operation_Ghost_Dukes.pdf
- https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html
- https://labs.sentinelone.com/noblebaron-new-poisoned-installers-could-be-used-in-supply-chain-attacks/
- https://www.mandiant.com/resources/blog/unc3524-eye-spy-email
- https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/microsoft-threat-actor-naming?view=o365-worldwide
- https://www.microsoft.com/security/blog/2018/12/03/analysis-of-cyberattack-on-u-s-think-tanks-non-profits-public-sector-by-unidentified-attackers/
- https://www.microsoft.com/security/blog/2021/05/27/new-sophisticated-email-based-attack-from-nobelium/
- https://msrc-blog.microsoft.com/2021/06/25/new-nobelium-activity/
- https://www.microsoft.com/security/blog/2021/05/28/breaking-down-nobeliums-latest-early-stage-toolset/
- https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/
- https://www.ncsc.gov.uk/files/Advisory-APT29-targets-COVID-19-vaccine-development-V1-1.pdf
- https://www.ncsc.gov.uk/files/Advisory-further-TTPs-associated-with-SVR-cyber-actors.pdf
- https://media.defense.gov/2021/Apr/15/2002621240/-1/-1/0/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF
- https://www.pwc.co.uk/issues/cyber-security-services/insights/wellmess-analysis-command-control.html
- https://www.pwc.co.uk/issues/cyber-security-services/insights/cleaning-up-after-wellmess.html
- http://www.secureworks.com/research/threat-profiles/iron-hemlock
- https://www.sophos.com/en-us/threat-profiles/iron-ritual
- https://www.gov.uk/government/news/russia-uk-and-us-expose-global-campaigns-of-malign-activity-by-russian-intelligence-services
- https://www.gov.uk/government/news/russia-uk-exposes-russian-involvement-in-solarwinds-cyber-compromise
- https://www.ncsc.gov.uk/news/uk-and-us-call-out-russia-for-solarwinds-compromise
- https://unit42.paloaltonetworks.com/solarstorm-supply-chain-attack-timeline/
- https://www.whitehouse.gov/briefing-room/statements-releases/2021/04/15/fact-sheet-imposing-costs-for-harmful-foreign-activities-by-the-russian-government/
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from APT29 into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.