NEW: Group Profiler — instant APT intel lookup. Try it →

APT29

G0016 Russia Espionage MITRE ATT&CK →

Also known as: IRON RITUAL · IRON HEMLOCK · NobleBaron · Dark Halo · NOBELIUM · UNC2452 · YTTRIUM · The Dukes · Cozy Bear · CozyDuke · SolarStorm · Blue Kitsune · UNC3524 · Midnight Blizzard

Overview

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015. In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.

Naming & attribution

APT29 is tracked under 15 names across the industry. It uses 66 documented ATT&CK techniques — more than 91% of the 174 groups tracked here. Activity attributed since at least 2008.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
IRON RITUALSecureworks CTU
IRON HEMLOCKSecureworks CTU
NobleBaronGuerrero-Saade, J
Dark HaloCash, D. et al
NOBELIUMNafisi, R., Lelli, A
UNC2452FireEye
YTTRIUMMicrosoft Defender Research Team
The DukesF-Secure Labs
Cozy BearAlperovitch, D.
CozyDukeAlperovitch, D.
SolarStormUnit 42
Blue KitsunePWC
UNC3524Mandiant
Midnight BlizzardMicrosoft
APT29F-Secure Labs

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1027.006 HTML Smuggling — used by 1 of 174 groups
  • T1090.004 Domain Fronting — used by 1 of 174 groups
  • T1098.005 Device Registration — used by 1 of 174 groups
  • T1556.007 Hybrid Identity — used by 1 of 174 groups
  • T1649 Steal or Forge Authentication Certificates — used by 1 of 174 groups
  • T1685.002 Disable or Modify Cloud Log — used by 1 of 174 groups
  • T1087.004 Cloud Account — used by 2 of 174 groups
  • T1136.003 Cloud Account — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • APT28 Russia — 29 shared techniques (22% overlap)
  • TA2541 — 16 shared techniques (21% overlap)
  • APT33 Iran — 16 shared techniques (20% overlap)
  • Threat Group-3390 China — 20 shared techniques (19% overlap)
  • Magic Hound Iran — 22 shared techniques (18% overlap)
  • VOID MANTICORE Iran — 20 shared techniques (18% overlap)

Malware families with current indicators

7 families attributed to APT29, carrying 1,620 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Sliver 1,562 indicators
  • Miniduke 41 indicators
  • SUNBURST 9 indicators
  • TEARDROP 4 indicators
  • GoldMax 2 indicators
  • CosmicDuke 1 indicators
  • WellMess 1 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Government · Private sector · Think Tanks

Regions

Belgium · Brazil · China · Georgia · Germany · India · Japan · Kazakhstan · Mexico · New Zealand · Portugal · Romania · South Korea · Turkey · Ukraine · United States

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190, T1203
  • Custom malware/implant development — ATT&CK: 34 attributed custom malware families

TTPs — 66 techniques across 13 tactics

Reconnaissance

Resource Development

Stealth

Defense Impairment

Discovery

Lateral Movement

Collection

Command and Control

Tools & malware (49)

PinchDuke · ROADTools · WellMail · CozyCar · Mimikatz · meek · TrailBlazer · Tasklist · OnionDuke · FatDuke · POSHSPY · EnvyScout · SoreFang · GeminiDuke · reGeorg · BloodHound · GoldMax · FoggyWeb · SDelete · PolyglotDuke · AADInternals · MiniDuke · TEARDROP · SeaDuke · Sibot · Raindrop · RegDuke · CloudDuke · GoldFinder · AdFind · PsExec · Tor · NativeZone · Systeminfo · ipconfig · SUNSPOT · Impacket · Cobalt Strike · PowerDuke · Net · QUIETEXIT · HAMMERTOSS · BoomBox · Sliver · CosmicDuke · SUNBURST · WellMess · VaporRage · LiteDuke

Reporting (3)