APT29, also known as Cozy Bear or The Dukes, has continued a long-running cyberespionage campaign against government and diplomatic targets in Europe and the United States, using successive Duke-family malware strains including MiniDuke, CozyDuke, Seaduke, OnionDuke, PolyglotDuke, RegDuke, FatDuke, and CosmicDuke. Reporting links the activity to Russian SVR interests and shows the group repeatedly focusing on ministries of foreign affairs, embassies, policy organizations, and other high-value institutions, with operations stretching from earlier intrusions against select government victims to later compromises of European foreign ministries and an EU-country embassy in Washington, DC.

TTPs, infrastructure, and targeting history in one profile.
15 events from the most recent confirmed update back to the earliest known activity.
Cyfirma analyzed an August 2022 CosmicDuke sample masquerading as a Google Chrome updater that unpacked payloads in memory, established persistence, and communicated with attacker infrastructure.
Cyfirma said the 'Natural Disaster' campaign associated with CosmicDuke was potentially active since March 17, 2022, with the stated goal of exfiltrating sensitive databases and customer information.
ESET disclosed Operation Ghost in 2019 and said it had uncovered three new Dukes malware families—PolyglotDuke, RegDuke, and FatDuke—used in a long-running campaign against European foreign ministries and an EU embassy in Washington, DC.
A later technical analysis described a previously undocumented MiniDuke backdoor sample dated June 2019, detailing its obfuscation and multiple exfiltration methods.
ESET reported that the latest observed sample in Operation Ghost was deployed in June 2019, showing the Dukes' campaign remained active years after its start.
A VirusTotal entry analyzed on 2014-11-15 showed a suspicious file detected by 19 of 55 antivirus engines, with multiple vendors classifying it as OnionDuke-related malware.
Symantec reported that Seaduke first appeared in target networks in October 2014 as a stealthy follow-on implant used against select high-value victims.
ESET said one of the first public traces of Operation Ghost appeared on Reddit in July 2014, where a post contained an encoded command-and-control URL used by PolyglotDuke.
In July 2014, the Duke group instructed CozyDuke-infected computers to install Miniduke on a compromised network, adding persistence and another exploitation path.
Symantec reported that successful compromises of high-profile government networks occurred in July 2014, with CozyDuke used to harvest and exfiltrate sensitive information.
Symantec said the group's then-current campaign began as early as March 2014, when CozyDuke was identified on the network of a private research institute in Washington, D.C.
ESET assessed that the Dukes' long-running Operation Ghost campaign likely began in 2013, preceding its later public exposure and continuing for years against diplomatic targets.
Symantec assessed that the Duke cyberespionage group had been compromising governmental and diplomatic organizations since at least 2010.
EclecticIQ reported an ongoing phishing and malware campaign using German embassy-themed PDF lures against NATO-aligned ministries of foreign affairs and linked it with high confidence to APT29/The Dukes.
Symantec published research describing Seaduke as a stealthy information-stealing Trojan used by the Duke group after CozyDuke infections against high-value government-level targets in the US and Europe.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 31 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
blog.eclecticiq.com
Open sourcecyfirma.com
Open sourcecybergeeks.tech
Open sourcewelivesecurity.com
Open sourcecommunity.broadcom.com
Open sourcecontagiodump.blogspot.com
Open sourcef-secure.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.