All threat actorsAlert me
APT29
APT29 is a state-sponsored Russian cyber espionage group linked to the Foreign Intelligence Service (SVR). The group has targeted government networks in Europe and NATO countries, research institutions, and think tanks, with notable activities including the 2015 Democratic National Committee breach and the 2021 SolarWinds compromise. APT29 employs spear phishing and supply chain attacks, using custom malware such as BEACON and COZYCAR, and maintains persistent access through sophisticated command and control infrastructure.
Also known as
Blue Kitsune
Cozy Bear
CozyDuke
Dark Halo
IRON HEMLOCK
IRON RITUAL
Midnight Blizzard
NOBELIUM
NobleBaron
SolarStorm
The Dukes
UNC2452
UNC3524
YTTRIUM
Create a free account to see the reports
Sign in or create a free account to see every report that names APT29.
Create free account