← Threat Actors / Global / UNC3524
DOSSIER // UNC3524

UNC3524

▲ High Threat
Primary Aliases: APT29 COZY BEAR Midnight Blizzard Nobelium
Sponsor / State Affiliation Independent / Not Attributed
Primary Motivation Espionage
Active Timeline Unknown – Present
Confidence Rating 70% (Grounded)

Mandiant observed this group operating since December 2019. Its techniques partially overlap with multiple Russian-based espionage actors (APT28 and APT29). They are described as having a high level of operational security, low malware footprint, adept evasive skills, and a large Internet of Things (IoT) device botnet at their disposal.

⚔️ Weaponized CVE Matrix (0)

No specific weaponized CVEs currently mapped in the public baseline.

🎯 Target Sectors & Focus

Defense & Aerospace Government & Diplomacy Financial & Crypto Critical Infrastructure

🛡️ MITRE ATT&CK® Attack Lifecycle (8 TTPs)

📥 Download Navigator JSON

📰 Verified Campaigns & Intelligence Archive

🔔 Subscribe to Alerts
Copied to clipboard

LINK COPIED TO CLIPBOARD