FORENSIA

THREAT_ACTOR · G0016

APT29

Also known as: APT29, IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard

Profile

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015. In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.

MITRE ATT&CK ↗

Techniques

66 ATT&CK techniques attributed to this actor.

T1003.002 Security Account ManagerT1003.004 LSA SecretsT1005 Data from Local SystemT1016.001 Internet Connection DiscoveryT1021.007 Cloud ServicesT1027.001 Binary PaddingT1027.002 Software PackingT1027.006 HTML SmugglingT1036.005 Match Legitimate Resource Name or LocationT1037 Boot or Logon Initialization ScriptsT1037.004 RC ScriptsT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1059.001 PowerShellT1059.006 PythonT1059.009 Cloud APIT1068 Exploitation for Privilege EscalationT1070.004 File DeletionT1070.006 TimestompT1078 Valid AccountsT1078.003 Local AccountsT1078.004 Cloud AccountsT1087.004 Cloud AccountT1090.002 External ProxyT1090.003 Multi-hop ProxyT1090.004 Domain FrontingT1098.002 Additional Email Delegate PermissionsT1098.005 Device RegistrationT1105 Ingress Tool TransferT1110.001 Password GuessingT1110.003 Password SprayingT1114.002 Remote Email CollectionT1133 External Remote ServicesT1136.003 Cloud AccountT1190 Exploit Public-Facing ApplicationT1199 Trusted RelationshipT1203 Exploitation for Client ExecutionT1204.001 Malicious LinkT1204.002 Malicious FileT1218.005 MshtaT1505.003 Web ShellT1528 Steal Application Access TokenT1546.003 Windows Management Instrumentation Event SubscriptionT1546.008 Accessibility FeaturesT1547.001 Registry Run Keys / Startup FolderT1548.002 Bypass User Account ControlT1550.003 Pass the TicketT1553.005 Mark-of-the-Web BypassT1556.007 Hybrid IdentityT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1566.003 Spearphishing via ServiceT1568 Dynamic ResolutionT1573 Encrypted ChannelT1583.006 Web ServicesT1586.002 Email AccountsT1586.003 Cloud AccountsT1587.001 MalwareT1587.003 Digital CertificatesT1588.002 ToolT1595.002 Vulnerability ScanningT1621 Multi-Factor Authentication Request GenerationT1649 Steal or Forge Authentication CertificatesT1651 Cloud Administration CommandT1665 Hide InfrastructureT1685.002 Disable or Modify Cloud Log

Software

49 malware/tools attributed to this actor.

MimikatzPsExecHAMMERTOSSNetCozyCarPinchDukeGeminiDukeCosmicDukeMiniDukeOnionDukeSeaDukeCloudDukeTasklistSysteminfoipconfigPowerDukePOSHSPYCobalt StrikemeekTorSDeleteImpacketRegDukeFatDukeLiteDukeWellMessWellMailSoreFangPolyglotDukeBloodHoundAdFindSUNBURSTTEARDROPSUNSPOTRaindropGoldMaxSibotGoldFinderSliverEnvyScoutBoomBoxVaporRageNativeZoneFoggyWebAADInternalsTrailBlazerROADToolsQUIETEXITreGeorg

Related corpus activity

10,432 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to APT29.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-11837cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2025-0921cve852
cve-2013-3307cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2016-5681cve852
cve-2025-66478cve852
cve-2026-22584cve852
cve-2021-27076cve851
cve-2025-68670cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2025-23304cve852
cve-2021-4045cve851
cve-2020-22653cve852
cve-2020-22658cve852
cve-2022-47945cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,432.