APT29

MITRE ATT&CK: G0016 View on attack.mitre.org

Aliases: IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard, Group 100, COZY BEAR, Minidionis, SeaDuke, Grizzly Steppe, ATK7, Cloaked Ursa, TA421, ITG11, BlueBravo, Nobelium, UAC-0029, APT29

First seen
2008-01-01 00:00:00
Origin
RU
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
17 (15 malicious)
Last IoC activity
2026-09-01 16:34:17
Profile updated
2026-07-07 12:33:25

Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications defense-and-aerospace

Targeted regions: country_code:us country_code:gb country_code:de country_code:fr country_code:se country_code:no

Context

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015. In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.

Recent IoC activity

15 malicious indicators in Maltiverse are attributed to APT29 (G0016). The 15 most recently updated:

TypeIndicatorUpdatedSources
hostname edenparkweddings.com 2026-09-02 1
hostname setnewcreds.ukr.net.frge.io 2026-06-15 1
file sample atiagentCozyBear.bin 2026-05-14 2
hostname ukrprivatesite.frge.io 2026-04-20 1
hostname robot-876.frge.io 2026-04-20 1
file sample 381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c.bin 2026-04-13 4
file sample 2d8f73c1f2e5b803ad6716644361c20b51ba49fa79361ef0bc1ae3a735968459.exe 2026-02-24 2
file sample ae79aa17e6f3cc8e816e32335738b61b343e78c20abb8ae044adfeac5d97bf70.exe 2026-01-05 2
file sample libcef.dll 2025-12-22 2
file sample Invitation_Farewell_DE_EMB.pdf.bin.pdf 2025-12-17 2
file sample CCleanerDU.dll 2025-12-16 2
hostname silry.com 2025-08-11 1
hostname bakenhof.com 2025-08-11 1
hostname ophibre.com 2025-08-11 1
file sample bounty-65309813155761065 2025-07-30 2

Detection coverage

  • 195 YARA rules
  • 805 Sigma rules

Malware & tools used

  • Multi-Factor Authentication Request Generation (attack-pattern)
  • Security Account Manager (attack-pattern)
  • Tool (attack-pattern)
  • Domain Fronting (attack-pattern)
  • Steal Application Access Token (attack-pattern)
  • Dynamic Resolution (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Windows Management Instrumentation Event Subscription (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Cloud Account (attack-pattern)
  • Device Registration (attack-pattern)
  • Digital Certificates (attack-pattern)
  • Data from Local System (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Cloud Administration Command (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Cloud Accounts (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Malware (attack-pattern)
  • Web Services (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Boot or Logon Initialization Scripts (attack-pattern)
  • HTML Smuggling (attack-pattern)
  • File Deletion (attack-pattern)

Related threat objects

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • CrowdStrike — Bears Midst Intrusion Democratic National Committee (report)
  • labsblog.f-secure.com — The Dukes 7 Years Of Russian Cyber Espionage (report)
  • Mandiant — Rpt Apt29 Hammertoss (report)
  • us-cert.gov — Ar 17 20045 Enhanced Analysis Of Grizzly Steppe Activity (report)
  • Mandiant — Dissecting One Ofap (report)
  • cfr.org — Dukes (report)
  • pylos.co — Cozybear In From The Cold (report)
  • Microsoft — Analysis Of Cyberattack On U S Think Tanks Non Profits Public Sector By Unidentified Attackers (report)
  • secureworks.com — Iron Hemlock (report)
  • MITRE ATT&CK — G0016 (report)
  • Palo Alto Unit 42 — Cloaked Ursa (report)
  • go.recordedfuture.com — Cta 2023 0127 (report)
  • cip.gov.ua — Download (report)
  • Mandiant — Evasive Attacker Leverages Solarwinds Supply Chain Compromises With Sunburst Backdoor (report)
  • Microsoft — Goldmax Goldfinder Sibot Analyzing Nobelium Malware (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • us-cert.gov — Jar 16 20296A Grizzly%20Steppe 2016 1229 (report)
  • secureworks.com — Iron Hemlock (report)
  • labs.sentinelone.com — Noblebaron New Poisoned Installers Could Be Used In Supply Chain Attacks (report)
  • media.defense.gov — Csa Svr Targets Us Allies Uoo13234021 (report)
  • Microsoft — New Nobelium Activity (report)
  • Palo Alto Unit 42 — Solarstorm Supply Chain Attack Timeline (report)
  • CrowdStrike — Observations From The Stellarparticle Campaign (report)

Attributed from

  • APT29 Abuses Cloud Storage Services for Malware Delivery (campaign)
  • APT29 Cloud TTP Evolution (campaign)
  • APT29 TeamCity Exploits (campaign)
  • C0021 (campaign)
  • Operation Ghost (campaign)
  • Russian SVR Cyber Operations and Vulnerability Exploitation Activity (campaign)
  • SolarWinds Compromise (campaign)

External references