SVR is Russia’s Foreign Intelligence Service, a Russian state intelligence agency repeatedly attributed in the provided content as responsible for cyber espionage operations. The content identifies SVR cyber actors under multiple aliases including APT29, the Dukes, Cozy Bear, NOBELIUM, and Midnight Blizzard. It is described as one of the main sources of espionage threat to Switzerland alongside the GRU and China, and as a major Russian espionage actor targeting government, critical infrastructure, private sector, universities, telecommunications operators, and IT service providers. The provided reporting attributes the 2020 SolarWinds supply-chain compromise to the SVR. That campaign reportedly began as early as October 2019 or at least March 2020 depending on the source cited, affected U.S. government agencies, critical infrastructure, and private-sector organizations, and used a trojanized SolarWinds Orion component signed with SolarWinds’ legitimate certificate. The content states the SVR also used additional access methods beyond SolarWinds, including password spraying, password guessing, abuse of externally accessible administrative credentials, forged or abused authentication tokens, SAML token abuse, compromise of SAML signing certificates, and persistence through Azure/Microsoft 365 application service principals and federation trust modification. Reported tradecraft includes stealthy long-duration operations, DNS-based command and control, targeting of key personnel email accounts, anti-analysis delays, and possible steganography. The content also states that SVR cyber actors exploited JetBrains TeamCity vulnerability CVE-2023-42793 at large scale beginning in September 2023, targeting unpatched internet-reachable on-premises TeamCity servers globally. Authorities assessed this access could enable software supply-chain compromise by exposing source code, signing certificates, and build/deployment processes, although the cited advisories state they had not observed SolarWinds-like downstream supply-chain abuse from this activity. Observed post-exploitation behavior included privilege escalation, lateral movement, persistence via scheduled tasks, credential theft including registry hive exfiltration and Mimikatz, Active Directory enumeration, disabling antivirus and EDR including BYOVD/EDRSandBlast techniques, and long-term access using Kerberos ticket abuse with Rubeus. The SVR used the GraphicalProton backdoor, including variants using Microsoft OneDrive and Dropbox for C2 and exfiltration, with data hidden inside randomly generated BMP files; other variants used DLL hijacking via Zabbix or hid activity within vcperf. The content also references use of a modified reverse SOCKS tunneler. The content further notes that the SVR allegedly hacked the Democratic National Committee network in 2015, though it was not named in the 2018 Mueller indictment focused on GRU activity. Overall, the provided material characterizes the SVR as a patient, well-resourced, highly capable Russian espionage actor focused on stealing confidential and proprietary information and maintaining stealthy, persistent access in victim environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The U.S. Federal Bureau of Investigation (FBI), ... assess Russian Foreign Intelligence Service (SVR) cyber actors ... are exploiting CVE-2023-42793 at a large scale, targeting servers hosting JetBrains TeamCity software since September 2023.
"By exploiting multiple Pulse Secure VPN weaknesses (CVE-2019-11510, CVE-2020-8260, CVE-2020-8243, and CVE-2021-22893), UNC2630 is said to have harvested login credentials..." ... "...advisory, warning businesses of active exploitation of five publicly known vulnerabilities by the Russian Foreign Intelligence Service (SVR), including CVE-2019-11510..."
161 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian state intelligence service identified as a principal espionage threat to Switzerland, including cyber-enabled espionage and broader hybrid activity.
Attributed (in this content) with the 2020 SolarWinds supply-chain compromise enabling long-term access into multiple Western government agencies.
Referenced for adapting tactics to obtain initial access in cloud environments.
Exploited a TeamCity vulnerability (CVE-2023-42793) to gain access, move laterally within victim networks, and deploy backdoors (GraphicalProton) to enable follow-on operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.