GTG-20006 is a Russian state-sponsored cyber-espionage cluster assessed to align with Midnight Blizzard, also known as APT29 and Cozy Bear. It has targeted Ukrainian and European government, military-intelligence, diplomatic, defense-industrial, think-tank, and drone-manufacturing organizations, as well as individuals connected to U.S. foreign policy. Additional activity has affected Middle Eastern, Asian maritime-government, and North African government entities. The group has employed phishing, ClickFix lures, compromised hospitality Wi-Fi providers and DNS manipulation to deliver Windows and mobile malware, conduct credential theft, and redirect victims to attacker infrastructure. It has used stolen administrative credentials to alter DNS configurations and identify further targets from hotel-management and guest-device data. GTG-20006 has also stolen Microsoft 365 tokens through device-code phishing, hijacked WhatsApp accounts through headless-browser companion-device linking, harvested conversations, exploited authorization weaknesses in surveillance platforms to access camera streams, and exfiltrated large government identity and commercial-registry datasets. Its operations have used AI-assisted workflows for reconnaissance, phishing-infrastructure setup, malware development and rebuilding, command-and-control monitoring, and iterative evasion of security detections. The hotel Wi-Fi DNS-hijacking activity overlaps with CaptiveCrunch.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
49 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian state-sponsored cyber-espionage activity using Claude-enabled AI workflows to monitor detections and autonomously modify, rebuild, and redeploy malware. The group targeted government, military intelligence, diplomatic, defense, and Ukraine-connected individuals and organizations; it also compromised hotel Wi-Fi vendors for DNS hijacking and delivered device-specific malware, conducted cloud-email and WhatsApp espionage, and accessed surveillance-camera streams.
Russian state-linked espionage activity that used AI agents to automate phishing infrastructure, malware development and iterative evasion, command-and-control, DNS hijacking, WhatsApp account compromise, and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.