APT29 (Comprehensive Profile) — Threat Intelligence Wiki
    Threat Intelligence Wiki Article  |  Talk     Read  |  View source  |  View history

    APT29

    From Threat Intelligence Wiki, the definitive threat-actor encyclopedia
    APT29
    🏰
    Operational Focus: Foreign Intelligence & Cloud
    Also known asMidnight Blizzard · Nobelium · Cozy Bear · The Dukes · Iron Hemlock · Grizzly Steppe
    Formationc. 2008
    Alleged ParentSVR (Foreign Intelligence Service of Russia)
    Operational AimStrategic Espionage, Foreign Policy Intelligence
    Primary TargetsGovernment, Diplomatic, NATO, Cloud Providers
    AttributionHigh Confidence (US IC, UK NCSC)
    Status● Critical Threat (Active)

    APT29 is a highly sophisticated cyber-espionage group attributed to the Foreign Intelligence Service of the Russian Federation (SVR). Unlike its counterparts in the GRU (such as APT28), APT29 is characterized by its extreme stealth, patience, and operational discipline. The group’s primary mission is the collection of intelligence to support Russian foreign policy, focusing heavily on Western governments, NATO, and diplomatic entities.[1]

    The group gained global notoriety for the 2020 SolarWinds supply-chain compromise, an operation that demonstrated an unprecedented level of technical proficiency and scale. Since 2021, APT29 has shifted its primary focus toward Cloud and SaaS infrastructure, specializing in bypassing modern identity protections to maintain long-term access to corporate and government email environments.[2]

    Vendor Naming Conventions:
    Midnight Blizzard (Microsoft) · Nobelium (Microsoft post-SolarWinds) · Cozy Bear (CrowdStrike) · The Dukes (Volexity/F-Secure) · Dark Halo (Volexity) · Iron Hemlock (Secureworks)

    1 Identity & Affiliation [edit]

    APT29 is believed to operate on behalf of the SVR, Russia’s civilian foreign intelligence agency. This affiliation dictates their tradecraft: while GRU actors (APT28) often conduct “Hack and Leak” operations for influence, APT29 focuses on “Quiet Intelligence”—stealing data and remaining undetected for as long as possible (often years).

    • The SVR Connection: In April 2021, the United States officially attributed the SolarWinds attack to the SVR, identifying APT29 as the operational arm.
    • Operational Methodology: They are known for “living off the land” within cloud environments and using residential proxies to hide their true origin, often appearing as legitimate users from within the target’s country.

    2 Technical Tradecraft & TTPs [edit]

    APT29’s tradecraft has evolved from traditional malware implants to sophisticated identity-based exploitation.

    Supply Chain Compromise (T1195)

    The group pioneered the modern supply-chain attack. By inserting a backdoor (SUNBURST) into a signed update of SolarWinds Orion software, they gained access to 18,000 organizations, including US Treasury, State, and Defense departments, without ever needing to phish a single user directly.[3]

    Token Theft & Identity Replay (T1550)

    Once inside a network, APT29 frequently targets Microsoft Entra ID (Azure AD). They utilize techniques to steal session tokens or forge “Golden SAML” tokens, allowing them to bypass Multi-Factor Authentication (MFA) and access cloud resources as a fully authenticated user.

    3 Key Historical Campaigns [edit]

    Year Campaign / Incident Target & Method Impact
    2014-15 Operation Ghost Attacks on Washington D.C. think tanks and government agencies. Long-term data exfiltration
    2016 DNC Hack Compromised the Democratic National Committee (alongside APT28). Political intelligence theft
    2020 SolarWinds / SUNBURST Supply chain injection into Orion software updates. Global breach of 18k entities
    2021 USAID Phishing Compromised a Constant Contact account to send malspam. Trusted-source exploitation
    2023-24 Microsoft/HPE Breach Password spray against legacy accounts to access executive emails. Source code/Email access
    2024 German Political Parties Targeting German politicians with fake CDU dinner invitations. Ongoing espionage

    4 Malware Ecosystem [edit]

    The group utilizes a “Duke” based toolkit alongside modern, memory-only implants:

    FamilyPurposeCapabilities
    SUNBURSTSupply Chain BackdoorThe DLL-based backdoor used in the SolarWinds compromise.
    WellmessCross-platform RATWritten in Go/.NET; targets both Windows and Linux to steal research.
    FoggyWebExfiltration ToolA post-exploitation tool used to steal sensitive data from AD FS servers.
    CozyDukeModular BackdoorHistoric tool used for initial access and persistence via phishing.
    SunshuttleC2 StealthUsed for exfiltration while masquerading as legitimate web traffic.

    5 Specialized Cloud Exploitation [edit]

    In recent years, APT29 has transitioned into a “Cloud-First” actor. Their tactics include:

    “APT29 demonstrates a mastery of the Microsoft Graph API, using it to exfiltrate emails without triggering typical ‘large-scale download’ alerts.”
    • MFA Exhaustion: Bombarding users with MFA prompts until they accidentally click ‘Approve’.
    • Dormant Account Takeover: Identifying legacy or test accounts without MFA to gain an initial foothold.
    • OAuth App Abuse: Registering malicious OAuth applications to maintain permanent access to mailboxes without needing a user’s password.

    6 Detection & Mitigation [edit]

    Defending against APT29 requires shifting focus from “Malware Detection” to “Identity Threat Detection (ITDR).”

    • Strict Conditional Access: Restrict Entra ID logins to known, compliant devices and specific geographic locations.
    • FIDO2 Implementation: APT29 has proven capable of bypassing SMS and push-based MFA; hardware keys (YubiKeys) are the primary defense.
    • Monitor AD FS: Implement rigorous logging on Active Directory Federation Services to detect unauthorized token signing.
    • SIEM Cloud Logs: Specifically monitor for `Add service principal` or `Add member to role` events in O365/Azure.

    References [edit]

    1. NCSC UK: “Advisory on SVR targeting of government and diplomatic sectors.”
    2. Microsoft Threat Intelligence: “Midnight Blizzard: Tracking the evolution of Nobelium.”
    3. Mandiant: “Highly Sophisticated Intrusion Campaign – SolarWinds Analysis.”
    4. CISA: “AA21-110A: Russian SVR Targets U.S. and Foreign Organizations.”
    5. Volexity: “Dark Halo and the Great SolarWinds Heist.”
    Categories: Advanced Persistent Threats · Russian State Hacking · SVR · Supply Chain Attacks · Cloud Exploitation · Foreign Espionage
    This page was last synced August 2026. Data is synthesized from public CISA, NCSC, and commercial threat intelligence archives.