APT29 is a Russian state-sponsored cyber espionage threat actor widely attributed to the Foreign Intelligence Service of the Russian Federation (SVR). It is commonly known as APT29, Cozy Bear, The Dukes, NOBELIUM, Dark Halo, Cloaked Ursa, and Midnight Blizzard. The group has conducted long-running intelligence collection operations against governments, diplomatic missions, political organizations, think tanks, technology companies, IT service providers, and entities connected to NATO member states and broader Western policy interests. It has also been linked to major supply-chain and identity-centric intrusions, including the SolarWinds compromise. APT29 is characterized by disciplined operational security, stealth, and persistence, with a strong emphasis on espionage rather than overt disruption. The group has repeatedly targeted diplomatic and political intelligence, including executive agencies, foreign ministries, political parties, and defense-related organizations. It has also targeted cloud and identity infrastructure, reflecting mature tradecraft in hybrid and enterprise SaaS environments. Its tradecraft spans spearphishing, password spraying, abuse of valid accounts, OAuth and cloud application abuse, compromise of service principals, and post-compromise manipulation of federation and authentication infrastructure. Public reporting has associated the group with campaigns using malicious documents, PDFs, LNK files, and other user-execution lures, as well as credential theft and mailbox access operations. In cloud-focused intrusions, APT29 has abused non-production or weakly protected tenants, elevated application permissions, and identity-layer access paths that can evade endpoint-centric detection. APT29 has demonstrated deep expertise in identity attacks. Operations attributed to the group include abuse of OAuth applications, access to Exchange Online mailboxes, compromise of Azure AD and service principal trust relationships, and persistence through federation abuse such as Golden SAML-related tradecraft in the SolarWinds context. The group has also deployed post-compromise capabilities against Active Directory Federation Services, including malware such as MagicWeb, to manipulate authentication claims and bypass policy controls including multifactor authentication. The actor is also associated with sophisticated supply-chain and third-party compromise activity. In the SolarWinds operation, APT29 leveraged software supply-chain access and follow-on intrusion activity to reach selected downstream victims for espionage. Reporting has further linked the group to targeting technology providers and IT service firms as intermediaries for access to government and policy targets. APT29 uses a broad range of techniques for discovery, lateral movement, command and control, and defense evasion. Observed behaviors include account discovery in Active Directory through native administrative tooling and PowerShell cmdlets, use of HTTP and HTTPS for command and control and exfiltration, domain fronting in earlier operations, and runtime decoding or decryption of payloads. The group has also been observed leveraging public offensive security tooling and open-source frameworks to blend espionage activity with common red-team-like artifacts. Known malware and intrusion tooling associated with APT29 includes SUNBURST, GoldMax, Raindrop, FoggyWeb, and MagicWeb, alongside historical Dukes-linked malware families and related implants. Sub-clusters and campaign labels used by vendors and governments include NOBELIUM, Dark Halo, and Midnight Blizzard, which generally refer to the same broader SVR-linked activity set rather than wholly separate actors. Overall, APT29 is regarded as one of the most capable Russian intelligence cyber operators, notable for patient long-term access, careful evasion, strong cloud and identity tradecraft, and repeated strategic espionage against Western governmental, diplomatic, and policy ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
65 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
50 malware families attributed to this actor across reporting.
45 additional families tracked in Mallory.
43 CVEs this actor has used in observed campaigns. 43 of them exploited in the wild.
In its own advisory for the CVE-2023-50224 vulnerability, TP-Link said that many of its products are affected, but that all of them have reached end-of-life status, which means they are no longer supported by the company.
The following are the vulnerabilities exploited by APT29. CVE-2018-13379: Fortinet FortiOS SSL VPN Path Traversal Vulnerability.
The following are the vulnerabilities exploited by APT29. CVE-2019-11510: Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability.
The following are the vulnerabilities exploited by APT29. CVE-2019-19781: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability.
The following are the vulnerabilities exploited by APT29. CVE-2019-9670: Synacor Zimbra Collaboration (ZCS) Improper Restriction of XML External Entity Reference.
38 more CVEs tied to this actor tracked in Mallory.
348 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Example threat actor profile used to demonstrate AI enrichment of a spear-phishing campaign targeting NATO members and defense contractors.
Referenced as the threat actor used in a CyberDefenders/OpenCTI threat intelligence exercise focused on identifying the group's TTPs and IoCs.
Espionage-oriented activity using password spraying against a Microsoft tenant lacking MFA, followed by abuse of a compromised high-privilege test OAuth application to access employee email. The content also notes nation-state use of stealer logs for quiet access to diplomatic mail.
Referenced as another Russian intelligence-linked intrusion set observed targeting the same victim as APT28.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.