APT29
MITRE ATT&CK: G0016 View on attack.mitre.org
Aliases: IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard, Group 100, COZY BEAR, Minidionis, SeaDuke, Grizzly Steppe, ATK7, Cloaked Ursa, TA421, ITG11, BlueBravo, Nobelium, UAC-0029, APT29
- First seen
- 2008-01-01 00:00:00
- Origin
- RU
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 17 (15 malicious)
- Last IoC activity
- 2026-09-01 16:34:17
- Profile updated
- 2026-07-07 12:33:25
Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications defense-and-aerospace
Targeted regions: country_code:us country_code:gb country_code:de country_code:fr country_code:se country_code:no
Context
APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015. In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.
Recent IoC activity
15 malicious indicators in Maltiverse are attributed to APT29 (G0016). The 15 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | edenparkweddings.com | 2026-09-02 | 1 |
| hostname | setnewcreds.ukr.net.frge.io | 2026-06-15 | 1 |
| file sample | atiagentCozyBear.bin | 2026-05-14 | 2 |
| hostname | ukrprivatesite.frge.io | 2026-04-20 | 1 |
| hostname | robot-876.frge.io | 2026-04-20 | 1 |
| file sample | 381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c.bin | 2026-04-13 | 4 |
| file sample | 2d8f73c1f2e5b803ad6716644361c20b51ba49fa79361ef0bc1ae3a735968459.exe | 2026-02-24 | 2 |
| file sample | ae79aa17e6f3cc8e816e32335738b61b343e78c20abb8ae044adfeac5d97bf70.exe | 2026-01-05 | 2 |
| file sample | libcef.dll | 2025-12-22 | 2 |
| file sample | Invitation_Farewell_DE_EMB.pdf.bin.pdf | 2025-12-17 | 2 |
| file sample | CCleanerDU.dll | 2025-12-16 | 2 |
| hostname | silry.com | 2025-08-11 | 1 |
| hostname | bakenhof.com | 2025-08-11 | 1 |
| hostname | ophibre.com | 2025-08-11 | 1 |
| file sample | bounty-65309813155761065 | 2025-07-30 | 2 |
Detection coverage
- 195 YARA rules
- 805 Sigma rules
Malware & tools used
- Multi-Factor Authentication Request Generation (attack-pattern)
- Security Account Manager (attack-pattern)
- Tool (attack-pattern)
- Domain Fronting (attack-pattern)
- Steal Application Access Token (attack-pattern)
- Dynamic Resolution (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Windows Management Instrumentation Event Subscription (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Cloud Account (attack-pattern)
- Device Registration (attack-pattern)
- Digital Certificates (attack-pattern)
- Data from Local System (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Cloud Administration Command (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Cloud Accounts (attack-pattern)
- Scheduled Task (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Malware (attack-pattern)
- Web Services (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Boot or Logon Initialization Scripts (attack-pattern)
- HTML Smuggling (attack-pattern)
- File Deletion (attack-pattern)
Related threat objects
- UNC2452 (threat-actor)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- CrowdStrike — Bears Midst Intrusion Democratic National Committee (report)
- labsblog.f-secure.com — The Dukes 7 Years Of Russian Cyber Espionage (report)
- Mandiant — Rpt Apt29 Hammertoss (report)
- us-cert.gov — Ar 17 20045 Enhanced Analysis Of Grizzly Steppe Activity (report)
- Mandiant — Dissecting One Ofap (report)
- cfr.org — Dukes (report)
- pylos.co — Cozybear In From The Cold (report)
- Microsoft — Analysis Of Cyberattack On U S Think Tanks Non Profits Public Sector By Unidentified Attackers (report)
- secureworks.com — Iron Hemlock (report)
- MITRE ATT&CK — G0016 (report)
- Palo Alto Unit 42 — Cloaked Ursa (report)
- go.recordedfuture.com — Cta 2023 0127 (report)
- cip.gov.ua — Download (report)
- Mandiant — Evasive Attacker Leverages Solarwinds Supply Chain Compromises With Sunburst Backdoor (report)
- Microsoft — Goldmax Goldfinder Sibot Analyzing Nobelium Malware (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- us-cert.gov — Jar 16 20296A Grizzly%20Steppe 2016 1229 (report)
- secureworks.com — Iron Hemlock (report)
- labs.sentinelone.com — Noblebaron New Poisoned Installers Could Be Used In Supply Chain Attacks (report)
- media.defense.gov — Csa Svr Targets Us Allies Uoo13234021 (report)
- Microsoft — New Nobelium Activity (report)
- Palo Alto Unit 42 — Solarstorm Supply Chain Attack Timeline (report)
- CrowdStrike — Observations From The Stellarparticle Campaign (report)
Attributed from
- APT29 Abuses Cloud Storage Services for Malware Delivery (campaign)
- APT29 Cloud TTP Evolution (campaign)
- APT29 TeamCity Exploits (campaign)
- C0021 (campaign)
- Operation Ghost (campaign)
- Russian SVR Cyber Operations and Vulnerability Exploitation Activity (campaign)
- SolarWinds Compromise (campaign)
External references
- mitre-attack — G0016
- CozyDuke
- Cozy Bear
- The Dukes
- APT29
- UNC2452
- UNC3524
- Midnight Blizzard
- YTTRIUM
- NOBELIUM
- Blue Kitsune
- IRON HEMLOCK
- IRON RITUAL
- NobleBaron
- SolarStorm
- Dark Halo
- Crowdstrike DNC June 2016
- Volexity SolarWinds
- CrowdStrike SUNSPOT Implant January 2021
- CrowdStrike StellarParticle January 2022