All threat actors

APT29 is a state-sponsored Russian cyber espionage group linked to the Foreign Intelligence Service (SVR). The group has targeted government networks in Europe and NATO countries, research institutions, and think tanks, with notable activities including the 2015 Democratic National Committee breach and the 2021 SolarWinds compromise. APT29 employs spear phishing and supply chain attacks, using custom malware such as BEACON and COZYCAR, and maintains persistent access through sophisticated command and control infrastructure.

Also known as

Blue Kitsune
Cozy Bear
CozyDuke
Dark Halo
IRON HEMLOCK
IRON RITUAL
Midnight Blizzard
NOBELIUM
NobleBaron
SolarStorm
The Dukes
UNC2452
UNC3524
YTTRIUM

Create a free account to see the reports

Sign in or create a free account to see every report that names APT29.

Create free account