APT29 is a Russian state-linked cyberespionage threat actor assessed to be associated with Russia’s Foreign Intelligence Service (SVR). It is widely tracked as Midnight Blizzard, Cozy Bear, NOBELIUM, The Dukes, Cloaked Ursa, BlueBravo, and UNC2452. The group has conducted long-running intelligence-collection operations against government, diplomatic, military, technology, and other strategically valuable targets. APT29 has used password spraying against inadequately protected cloud identities, lateral movement between cloud tenants, and abuse of legacy OAuth applications and highly privileged application permissions to obtain access to Exchange Online mailboxes. It has established cloud persistence through compromised virtual machines, command-and-control infrastructure, and newly created credentials for service principals. The actor has also used scheduled tasks for persistence and has targeted Zimbra environments, including operations intended to obtain email-account credentials. Reported Midnight Blizzard activity includes social-engineering operations against hotel and conference-center Wi-Fi infrastructure. These operations compromise network gateways or captive-portal components, manipulate DNS resolution, use ClickFix-style lures, and abuse Microsoft Entra ID device-code authentication to obtain OAuth tokens and circumvent multifactor authentication without acquiring plaintext passwords. Associated malware capabilities include keylogging, audio surveillance, and browser-cookie theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
61 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
46 malware families attributed to this actor across reporting.
41 additional families tracked in Mallory.
38 CVEs this actor has used in observed campaigns. 38 of them exploited in the wild.
CVE-2023-42793 in JetBrains TeamCity is identified as exploited by APT29 and Lazarus.
The following are the vulnerabilities exploited by APT29. CVE-2018-13379: Fortinet FortiOS SSL VPN Path Traversal Vulnerability.
The following are the vulnerabilities exploited by APT29. CVE-2019-11510: Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability.
In a separate incident, SVR actors used CVE-2019-19781, a zero-day exploit at the time, against a virtual private network (VPN) appliance to obtain network access. Following exploitation of the device in a way that exposed user credentials, the actors identified and authenticated to systems on the network using the exposed credentials.
The following are the vulnerabilities exploited by APT29. CVE-2019-9670: Synacor Zimbra Collaboration (ZCS) Improper Restriction of XML External Entity Reference.
33 more CVEs tied to this actor tracked in Mallory.
639 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian state-sponsored cyberespionage operation compromising hotel and conference-center Wi-Fi routers and captive portals, poisoning DNS to redirect victims to malicious servers, and using social engineering and Entra ID authentication abuse to obtain access.
Mentioned only as a comparison to prior Microsoft Teams-based attacks involving credential harvesting and group-chat social engineering.
Russia-linked state-sponsored actor cited as exploiting the JetBrains TeamCity vulnerability CVE-2023-42793, independently of Lazarus.
A Russia-nexus state-sponsored actor independently exploiting the JetBrains TeamCity vulnerability CVE-2023-42793.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.