APT29 is a Russia-linked espionage threat actor publicly associated with the Russian Foreign Intelligence Service (SVR). Widely tracked under aliases including Cloaked Ursa, Midnight Blizzard, Nobelium, Cozy Bear, and UAC-0004, the group is known for long-running intelligence collection operations against diplomatic, government, and related foreign-policy targets worldwide. APT29 has conducted highly targeted spear-phishing and social-engineering campaigns and has also adapted to cloud- and collaboration-centric intrusion tradecraft. Reported operations include abuse of compromised accounts to send malicious Microsoft Teams messages that redirect victims to credential-harvesting pages, as well as spear-phishing used to gain access before internal Microsoft 365 and Entra ID tenant exploration. The group has been observed leveraging ROADtools-related capabilities for cloud reconnaissance and post-compromise identity abuse, including enumeration of tenant resources through legitimate Microsoft APIs. The actor has targeted diplomatic missions extensively, including foreign embassies in Kyiv and Turkish foreign-affairs-related entities, using lures tailored to diplomats’ professional and personal interests. In 2023 campaigns, APT29 used themed documents and links to deliver multi-stage malware chains involving HTML application delivery, disk image files, shortcut-based execution, and DLL sideloading. Reported payload behavior included anti-analysis checks, shellcode execution, process injection, command execution, file read/write capability, and command-and-control over legitimate cloud services and APIs. Malware and tradecraft overlaps have been noted with tooling such as QUARTERRIG. APT29 is characterized by stealth, careful victim selection, and strong operational security, with emphasis on credential theft, cloud identity abuse, persistence, reconnaissance, defense evasion, and post-exploitation in support of strategic intelligence collection rather than financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses compromised accounts and Microsoft Teams-based social engineering to send malicious links that redirect victims to credential-harvesting pages impersonating Microsoft login portals.
Used ROADtools in a 2021 campaign, employing spear phishing followed by internal cloud tenant reconnaissance.
Used ROADtools in cloud intrusions after initial access via spear phishing, leveraging it for discovery, persistence, and defense evasion in Microsoft Azure/Entra ID environments.
Conducting cyber espionage against diplomatic missions, particularly foreign embassies and ministries connected to Ukraine, using spear-phishing lures themed around diplomats’ personal needs and humanitarian guidance to deliver multi-stage malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.