NOBELIUM, also tracked as NobleBaron and internally as Blue Dev 5, is a Russia-linked state-sponsored espionage threat actor known for sophisticated intrusions focused on cloud, identity, and supply-chain access. The actor has conducted operations against government and diplomatic targets and has also compromised managed service providers and cloud service providers to reach downstream victims through trusted relationships. The group is notable for advanced identity-centric tradecraft, including evasion of multifactor authentication through abuse of dormant accounts and privileged cloud access, as well as compromise of Microsoft cloud environments, Azure Active Directory, and Office 365 tenants. NOBELIUM has used phishing in targeted campaigns, including operations impersonating trusted organizations, and has deployed multi-stage payloads with Cobalt Strike during post-compromise activity. Reported operations also include data exfiltration from cloud-hosted environments and exploitation of inter-organizational trust relationships to expand access. NOBELIUM is widely associated with Russian state interests and is assessed to operate primarily for espionage. Its activity reflects a high level of operational discipline, careful victim selection, and emphasis on stealthy access to strategic information rather than disruptive or financially motivated outcomes.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian group conducting sophisticated cloud-based espionage, targeting MSPs and cloud environments.
Blue Dev 5 is an advanced persistent threat group known for targeting cloud environments, evading MFA, and compromising service providers to access Microsoft Azure and O365 tenants.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.