Dark Halo is a state-sponsored espionage threat actor tracked in connection with intrusions against a US-based think tank and activity overlapping with the SolarWinds supply-chain compromise. The actor has been publicly associated with the cluster also tracked as UNC2452 and has been linked by multiple public reports to APT29, also known as Cozy Bear, a Russian intelligence-associated threat group widely believed to operate on behalf of the Russian state. Dark Halo is characterized by patient, high-skill, long-duration operations focused primarily on intelligence collection, especially theft of email from selected executives, policy experts, and IT personnel. The actor has demonstrated the ability to maintain persistence for extended periods, re-enter victim environments after remediation, and minimize forensic visibility through selective tooling, cleanup of artifacts, and extensive use of legitimate administrative utilities and native system functionality. Observed tradecraft includes compromise of Microsoft Exchange environments, abuse of Outlook Web App and Exchange administrative interfaces, reconnaissance through Exchange Management Shell PowerShell cmdlets, mailbox export operations, manipulation of ActiveSync settings to authorize attacker-controlled devices, lateral movement via PowerShell and scheduled tasks, and staged exfiltration of collected mail data through Exchange web infrastructure. Dark Halo has also been observed using renamed legitimate tools for directory reconnaissance and relying heavily on living-off-the-land techniques rather than noisy malware deployment when possible. A notable technique attributed to Dark Halo involved bypassing Duo-protected multi-factor authentication for Outlook Web App after deep compromise of the target server. By obtaining the MFA integration secret stored on the compromised server, the actor was able to generate a valid MFA-related session value and access a mailbox using valid credentials without triggering a second-factor challenge. This behavior reflected compromise of trusted integration material within the victim environment rather than exploitation of a vulnerability in the MFA product itself. Dark Halo has been described as highly sophisticated, persistent, and operationally disciplined. Known aliases and related tracking names include UNC2452, APT29, and Cozy Bear.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
68 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromised an OWA server and bypassed Duo-protected MFA by obtaining the Duo integration secret key (akey) from the server and forging a valid duo-sid cookie after successful password authentication.
State-sponsored threat actor linked here to the supply chain attack that compromised public and private organizations. The group repeatedly penetrated a think tank, maintained long-term undetected access, and bypassed Duo MFA by stealing the Duo integration secret key (akey) from an Outlook Web App server and generating a valid duo-sid cookie.
Conducted repeated intrusions into a think tank and used privileged access on an Outlook Web App server to steal a Duo integration secret (akey), generate a valid duo-sid cookie, and bypass MFA in order to access targeted email accounts and remain undetected for extended periods.
Compromised an OWA server and bypassed Duo-protected MFA by obtaining the Duo integration secret key (akey) from the server and generating a valid duo-sid cookie, allowing access with only username and password.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.