APT29
G001615 reportsAnalyst assessment — key judgments
- Signature techniques: T1589.001 (Credentials), T1684 (Social Engineering), T1059.001 (PowerShell).
- Primary targeting: RU, US, UA, CN.
- Activity declining: 3 report(s) in last 30d vs 8 prior (-62%).
- Recent movement: 3 new technique(s), 2 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 54% of 50 observed techniques (23 gap(s)).
- Assessment confidence: medium (62).
Activity & trend
Movement — last 30 days
Vulnerabilities in this actor's reporting · 21
- CVE-2023-42793KEV1 rpt
- CVE-2024-24919KEV1 rpt
- CVE-2024-3400KEV1 rpt
- CVE-2024-47575KEV1 rpt
- CVE-2024-8190KEV1 rpt
- CVE-2024-8963KEV1 rpt
- CVE-2025-59718KEV1 rpt
- CVE-2026-1281KEV1 rpt
- CVE-2026-1340KEV1 rpt
- CVE-2026-15409KEV1 rpt
- CVE-2026-20316KEV1 rpt
- CVE-2026-24858KEV1 rpt
- CVE-2026-42897KEV1 rpt
- CVE-2026-59310KEV1 rpt
- CVE-2026-63077KEV1 rpt
- CVE-2023-341241 rpt
- CVE-2023-341321 rpt
- CVE-2023-341331 rpt
- CVE-2026-593091 rpt
- CVE-2026-597261 rpt
- CVE-2026-660661 rpt
Overview
APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).(Citation: White House Imposing Costs RU Gov April 2021)(Citation: UK Gov Malign RIS Activity April 2021) They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015.(Citation: F-Secure The Dukes)(Citation: GRIZZLY STEPPE JAR)(Citation: Crowdstrike DNC June 2016)(Citation: UK Gov UK Exposes Russia SolarWinds April 2021)
In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes.(Citation: NSA Joint Advisory SVR SolarWinds April 2021)(Citation: UK NSCS Russia SolarWinds April 2021) Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.(Citation: FireEye SUNBURST Backdoor December 2020)(Citation: MSTIC NOBELIUM Mar 2021)(Citation: CrowdStrike SUNSPOT Implant January 2021)(Citation: Volexity SolarWinds)(Citation: Cybersecurity Advisory SVR TTP May 2021)(Citation: Unit 42 SolarStorm December 2020)
ATT&CK technique matrix
- T1589.001 · Credentialsconf 7511
- T1684 · Social Engineeringconf 705
- T1059.001 · PowerShellconf 705
- T1557 · Adversary-in-the-Middleconf 704
- T1590.005 · IP Addressesconf 704
- T1588.006 · Vulnerabilitiesconf 754
- T1059.007 · JavaScriptconf 704
- T1556.009 · Conditional Access Policiesconf 653
- T1036 · Masqueradingconf 653
- T1098.005 · Device Registrationconf 653
- T1684.001 · Impersonationconf 653
- T1669 · Wi-Fi Networksconf 653
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|