← All Threat Actors
Threat Actor Profile

APT29

ATK7 Blue Kitsune BlueBravo Cloaked Ursa COZY BEAR CozyDuke Dark Halo G0016 Grizzly Steppe Group 100 IRON HEMLOCK IRON RITUAL ITG11 Midnight Blizzard Minidionis Nobelium NobleBaron SeaDuke SolarStorm TA421 The Dukes UAC-0029 UNC2452 UNC3524 YTTRIUM
⚠ Critical Threat
Microsoft Corporate Email Compromise, Cloud-Native Espionage Operations
Origin Russia
Sponsor Russian Federation (SVR)
Motivation Strategic Political and Diplomatic Espionage

Target Sectors

Government agencies Diplomatic entities Think tanks NATO member states Technology providers Healthcare and research institutions

Known TTPs

Password spraying
OAuth token abuse and manipulation
Living-off-the-cloud (LotC)
Exploitation of legacy non-production tenants
API-based data exfiltration
Supply chain compromise
Stealthy lateral movement within Microsoft 365 environments
Use of legitimate cloud services for C2

Related Intelligence


LINK COPIED TO CLIPBOARD