{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "apt29",
    "slug": "apt29",
    "name": "APT29",
    "shortName": "APT29",
    "country": "Russia",
    "countryCode": "RU",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2008",
    "prominence": 97,
    "mitreGroupId": "G0016",
    "malpediaSlug": "apt29",
    "tagline": "Russia's SVR foreign intelligence service. Executed the SolarWinds supply-chain compromise and remains the benchmark for patient, cloud-native espionage.",
    "bio": "APT29 belongs to the SVR, Russia's civilian foreign intelligence service — the institutional successor to the KGB's First Chief Directorate. It is the most operationally disciplined state actor tracked in the public record.\n\nThe group's defining characteristic is patience. Where APT28 burns infrastructure and accepts noise, APT29 will spend a year inside a network without triggering a single alert. The SolarWinds operation is the clearest expression of this: the actor compromised the build system in September 2019, spent a month testing a benign code injection to verify it would go unnoticed, and only then shipped the SUNBURST backdoor to some 18,000 downstream customers — from which it selected fewer than 100 for actual follow-on exploitation.\n\nSince 2021 APT29 has pivoted decisively toward identity and cloud. Rather than dropping malware on endpoints, it targets the authentication layer directly: stolen OAuth application consent, forged SAML assertions via the Golden SAML technique, service-principal abuse in Microsoft Entra ID, residential-proxy networks to defeat impossible-travel detection, and password spraying against legacy accounts without MFA. Its January 2024 breach of Microsoft's own corporate email began with a password spray against a legacy non-production test tenant.\n\nTargeting is strategic and narrow: foreign ministries, national security policy bodies, IT and cloud providers used as stepping stones, and — during 2020 — COVID-19 vaccine research at institutions in the U.S., UK, and Canada.",
    "attribution": {
      "sponsor": "Russia",
      "service": "SVR — Foreign Intelligence Service",
      "confidence": "confirmed",
      "summary": "Formally attributed to the SVR by the U.S. and UK governments in April 2021, concurrent with sanctions on Russia over the SolarWinds compromise. The U.S. Treasury designation, NSA/CISA/FBI joint advisory, and UK NCSC statement were issued the same day and name the SVR explicitly. Unlike the GRU groups, no individual SVR officers have been indicted, and no internal unit designator has been publicly established.",
      "sources": [
        {
          "org": "U.S. Department of the Treasury",
          "title": "Treasury Sanctions Russia with Sweeping New Sanctions Authority — SVR attribution for SolarWinds",
          "url": "https://home.treasury.gov/news/press-releases/jy0127",
          "date": "2021-04-15"
        },
        {
          "org": "NSA / CISA / FBI",
          "title": "Russian SVR Targets U.S. and Allied Networks",
          "url": "https://media.defense.gov/2021/Apr/15/2002621240/-1/-1/0/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF",
          "date": "2021-04-15"
        },
        {
          "org": "NCSC-UK",
          "title": "UK and US call out Russia for SolarWinds compromise",
          "url": "https://www.ncsc.gov.uk/news/uk-and-us-call-out-russia-for-solarwinds-compromise",
          "date": "2021-04-15"
        }
      ]
    },
    "motivations": [
      "espionage"
    ],
    "targetSectors": [
      "Government",
      "Diplomatic",
      "Technology",
      "Think Tanks & Academia",
      "Defense",
      "Healthcare",
      "Pharmaceuticals",
      "Managed Service Providers",
      "Energy",
      "NGO & Civil Society"
    ],
    "targetCountries": [
      "United States",
      "United Kingdom",
      "Germany",
      "Netherlands",
      "Norway",
      "Czechia",
      "Poland",
      "Canada",
      "Italy",
      "Ukraine"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "APT29",
        "url": "https://attack.mitre.org/groups/G0016/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Midnight Blizzard",
        "correlation": "exact",
        "note": "Formerly NOBELIUM"
      },
      {
        "org": "microsoft",
        "name": "NOBELIUM",
        "correlation": "exact",
        "note": "Retired designator"
      },
      {
        "org": "crowdstrike",
        "name": "Cozy Bear",
        "url": "https://www.crowdstrike.com/adversaries/cozy-bear/",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "APT29",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "UNC2452",
        "correlation": "partial",
        "note": "The SolarWinds intrusion cluster specifically; merged into APT29 in April 2022 after Mandiant assessed overlap"
      },
      {
        "org": "secureworks",
        "name": "IRON RITUAL",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "IRON HEMLOCK",
        "correlation": "partial",
        "note": "Tracks a related but distinct subset of SVR activity"
      },
      {
        "org": "unit42",
        "name": "Cloaked Ursa",
        "correlation": "exact"
      },
      {
        "org": "recordedfuture",
        "name": "BlueBravo",
        "correlation": "exact"
      },
      {
        "org": "eset",
        "name": "The Dukes",
        "correlation": "exact"
      },
      {
        "org": "kaspersky",
        "name": "The Dukes",
        "correlation": "exact"
      },
      {
        "org": "kaspersky",
        "name": "CozyDuke",
        "correlation": "partial",
        "note": "Refers to a specific implant family within the Dukes toolset"
      },
      {
        "org": "trendmicro",
        "name": "Earth Koshchei",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "SVR",
        "correlation": "exact"
      },
      {
        "org": "redcanary",
        "name": "Cozy Bear",
        "correlation": "exact",
        "note": "Adopts the prevailing community designator"
      }
    ],
    "tools": [
      {
        "name": "SUNBURST",
        "type": "backdoor",
        "custom": true,
        "description": "Trojanised SolarWinds Orion plugin. Dormant for 12–14 days after install, verified the victim domain against a blocklist before activating.",
        "malpediaSlug": "win.sunburst"
      },
      {
        "name": "TEARDROP",
        "type": "loader",
        "custom": true,
        "description": "Memory-only dropper deployed by SUNBURST to load a customised Cobalt Strike Beacon.",
        "malpediaSlug": "win.teardrop"
      },
      {
        "name": "RAINDROP",
        "type": "loader",
        "custom": true,
        "description": "Second-stage loader used for lateral movement in a subset of SolarWinds victims.",
        "malpediaSlug": "win.raindrop"
      },
      {
        "name": "FoggyWeb",
        "type": "backdoor",
        "custom": true,
        "description": "Post-exploitation backdoor for AD FS servers that exfiltrates the token-signing certificate — enabling arbitrary token forgery.",
        "malpediaSlug": "win.foggyweb"
      },
      {
        "name": "MagicWeb",
        "type": "backdoor",
        "custom": true,
        "description": "Malicious AD FS DLL allowing authentication as any user by injecting a claim into the token issuance pipeline."
      },
      {
        "name": "WINELOADER",
        "type": "backdoor",
        "custom": true,
        "description": "Modular backdoor delivered via wine-tasting-themed diplomatic lures across European foreign ministries.",
        "malpediaSlug": "win.wineloader"
      },
      {
        "name": "EnvyScout",
        "type": "loader",
        "custom": true,
        "description": "HTML smuggling dropper delivering an ISO or IMG container to bypass Mark-of-the-Web."
      },
      {
        "name": "GoldMax",
        "type": "backdoor",
        "custom": true,
        "description": "Go-based C2 backdoor masquerading as a scheduled system task, with an encrypted decoy traffic generator."
      },
      {
        "name": "WellMess",
        "type": "backdoor",
        "custom": true,
        "description": "Cross-platform Go/.NET implant used against COVID-19 vaccine research organisations.",
        "malpediaSlug": "elf.wellmess"
      },
      {
        "name": "Golden SAML",
        "type": "lotl",
        "custom": false,
        "description": "Forging SAML assertions with a stolen token-signing key to authenticate to cloud services as any user, bypassing MFA entirely."
      },
      {
        "name": "Cobalt Strike",
        "type": "framework",
        "custom": false,
        "description": "Commercial C2 framework with heavily customised malleable profiles and watermark-stripped beacons."
      },
      {
        "name": "AdFind",
        "type": "lotl",
        "custom": false,
        "description": "Legitimate Active Directory query tool used for domain reconnaissance."
      }
    ],
    "techniques": [
      {
        "tCode": "T1195.002",
        "name": "Supply Chain Compromise: Compromise Software Supply Chain",
        "tactic": "Initial Access",
        "note": "SolarWinds Orion build system compromise"
      },
      {
        "tCode": "T1078.004",
        "name": "Valid Accounts: Cloud Accounts",
        "tactic": "Initial Access",
        "note": "Primary access vector since 2021"
      },
      {
        "tCode": "T1110.003",
        "name": "Brute Force: Password Spraying",
        "tactic": "Credential Access",
        "note": "Low-and-slow spraying from residential proxies against legacy accounts lacking MFA"
      },
      {
        "tCode": "T1566.002",
        "name": "Phishing: Spearphishing Link",
        "tactic": "Initial Access",
        "note": "Signed RDP configuration files and device-code phishing"
      },
      {
        "tCode": "T1027.006",
        "name": "Obfuscated Files or Information: HTML Smuggling",
        "tactic": "Defense Evasion",
        "note": "EnvyScout"
      },
      {
        "tCode": "T1606.002",
        "name": "Forge Web Credentials: SAML Tokens",
        "tactic": "Credential Access",
        "note": "Golden SAML using stolen AD FS token-signing certificates"
      },
      {
        "tCode": "T1550.001",
        "name": "Use Alternate Authentication Material: Application Access Token",
        "tactic": "Lateral Movement",
        "note": "OAuth application consent abuse for persistent mailbox access"
      },
      {
        "tCode": "T1098.001",
        "name": "Account Manipulation: Additional Cloud Credentials",
        "tactic": "Persistence",
        "note": "Adding credentials to existing service principals"
      },
      {
        "tCode": "T1484.002",
        "name": "Domain or Tenant Policy Modification: Trust Modification",
        "tactic": "Privilege Escalation",
        "note": "Adding attacker-controlled federated trust domains"
      },
      {
        "tCode": "T1556.007",
        "name": "Modify Authentication Process: Hybrid Identity",
        "tactic": "Credential Access",
        "note": "MagicWeb and FoggyWeb on AD FS"
      },
      {
        "tCode": "T1497",
        "name": "Virtualization/Sandbox Evasion",
        "tactic": "Defense Evasion",
        "note": "SUNBURST domain blocklisting and long dormancy"
      },
      {
        "tCode": "T1090.002",
        "name": "Proxy: External Proxy",
        "tactic": "Command and Control",
        "note": "Residential proxy networks to match victim geolocation"
      },
      {
        "tCode": "T1102.002",
        "name": "Web Service: Bidirectional Communication",
        "tactic": "Command and Control",
        "note": "Trello, Dropbox, Google Drive, and Notion abused as C2"
      },
      {
        "tCode": "T1114.002",
        "name": "Email Collection: Remote Email Collection",
        "tactic": "Collection"
      },
      {
        "tCode": "T1070.004",
        "name": "Indicator Removal: File Deletion",
        "tactic": "Defense Evasion",
        "note": "Consistent anti-forensic hygiene; log clearing after each session"
      },
      {
        "tCode": "T1553.002",
        "name": "Subvert Trust Controls: Code Signing",
        "tactic": "Defense Evasion"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2023-42793",
        "firstExploited": "2023-09-01",
        "usage": "Mass exploitation of internet-facing JetBrains TeamCity servers to reach software build pipelines — the same strategic objective as SolarWinds, pursued opportunistically at scale. Prompted a joint advisory from five countries.",
        "source": {
          "org": "CISA / FBI / NSA / NCSC-UK / SKW-PL",
          "title": "Russian SVR Actors Target JetBrains TeamCity CVE Globally (AA23-347A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a",
          "date": "2023-12-13"
        }
      },
      {
        "cveId": "CVE-2019-11510",
        "firstExploited": "2020-04-01",
        "usage": "Pulse Secure file read used to harvest VPN credentials during the COVID-19 vaccine research targeting campaign.",
        "source": {
          "org": "NCSC-UK / CSE / NSA / CISA",
          "title": "Advisory: APT29 targets COVID-19 vaccine development",
          "url": "https://www.ncsc.gov.uk/files/Advisory-APT29-targets-COVID-19-vaccine-development-V1-1.pdf",
          "date": "2020-07-16"
        }
      },
      {
        "cveId": "CVE-2019-19781",
        "firstExploited": "2020-01-01",
        "usage": "Citrix ADC traversal exploited for initial access to enterprise perimeters.",
        "source": {
          "org": "NSA / CISA / FBI",
          "title": "Russian SVR Targets U.S. and Allied Networks",
          "url": "https://media.defense.gov/2021/Apr/15/2002621240/-1/-1/0/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF",
          "date": "2021-04-15"
        }
      },
      {
        "cveId": "CVE-2018-13379",
        "firstExploited": "2020-05-01",
        "usage": "FortiOS SSL VPN path traversal used to obtain plaintext VPN credentials from unpatched appliances.",
        "source": {
          "org": "NSA / CISA / FBI",
          "title": "Russian SVR Targets U.S. and Allied Networks",
          "url": "https://media.defense.gov/2021/Apr/15/2002621240/-1/-1/0/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF",
          "date": "2021-04-15"
        }
      },
      {
        "cveId": "CVE-2021-21972",
        "firstExploited": "2021-03-01",
        "usage": "VMware vCenter unauthenticated RCE listed among SVR-exploited vulnerabilities for initial access.",
        "source": {
          "org": "NSA / CISA / FBI",
          "title": "Russian SVR Targets U.S. and Allied Networks",
          "url": "https://media.defense.gov/2021/Apr/15/2002621240/-1/-1/0/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF",
          "date": "2021-04-15"
        }
      },
      {
        "cveId": "CVE-2020-1472",
        "firstExploited": "2020-10-01",
        "usage": "Zerologon used for domain escalation in intrusions following perimeter compromise.",
        "source": {
          "org": "CISA",
          "title": "Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
          "date": "2020-12-17"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "apt28",
        "type": "operational-overlap",
        "confidence": "confirmed",
        "note": "Simultaneous, apparently uncoordinated presence in the DNC network in 2016 — a well-documented instance of Russian services not deconflicting."
      },
      {
        "relatedActorId": "turla",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both conduct strategic espionage for Russian services; SVR and FSB respectively, with occasional target overlap in diplomatic networks."
      },
      {
        "relatedActorId": "star-blizzard",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Overlapping interest in policy, NGO, and think-tank targets, though Star Blizzard is FSB and far less capable."
      }
    ],
    "reports": [
      {
        "org": "Mandiant / FireEye",
        "title": "Highly Evasive Attacker Leverages SolarWinds Supply Chain (SUNBURST)",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor",
        "date": "2020-12-13"
      },
      {
        "org": "Microsoft Threat Intelligence",
        "title": "Midnight Blizzard: Nation-state attack on Microsoft corporate systems",
        "url": "https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/",
        "date": "2024-01-19"
      },
      {
        "org": "Mandiant",
        "title": "FoggyWeb: Targeted NOBELIUM malware leads to persistent backdoor on AD FS",
        "url": "https://www.microsoft.com/en-us/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/",
        "date": "2021-09-27"
      },
      {
        "org": "Mandiant",
        "title": "Assembling the Russian Nesting Dolls: UNC2452 Merged into APT29",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/unc2452-merged-into-apt29",
        "date": "2022-04-27"
      },
      {
        "org": "Unit 42",
        "title": "Cloaked Ursa: Diplomatic Phishing Using Car-for-Sale Lures",
        "url": "https://unit42.paloaltonetworks.com/cloaked-ursa-phishing/",
        "date": "2023-07-12"
      },
      {
        "org": "Mandiant",
        "title": "APT29 targets diplomats with WINELOADER via wine-tasting lures",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt29-wineloader-german-political-parties",
        "date": "2024-03-22"
      }
    ],
    "campaigns": [
      {
        "id": "midnight-blizzard-microsoft",
        "actorId": "apt29",
        "name": "Microsoft Corporate Email Breach",
        "date": "2023-11-01",
        "endDate": "2024-01-12",
        "significance": "major",
        "targetSectors": [
          "Technology",
          "Government"
        ],
        "targetCountries": [
          "United States"
        ],
        "cveIds": [],
        "summary": "Password spray against a legacy non-production test tenant without MFA, escalated via an OAuth application with elevated access to Microsoft corporate mailboxes — including members of the senior leadership team and the security and legal functions. Source code repositories were also accessed.",
        "sources": [
          {
            "org": "Microsoft Security Response Center",
            "title": "Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard",
            "url": "https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/",
            "date": "2024-01-19"
          }
        ]
      },
      {
        "id": "vaccine-research-2020",
        "actorId": "apt29",
        "name": "COVID-19 Vaccine Research Targeting",
        "date": "2020-04-01",
        "endDate": "2020-12-01",
        "significance": "major",
        "targetSectors": [
          "Healthcare",
          "Pharmaceuticals",
          "Think Tanks & Academia"
        ],
        "targetCountries": [
          "United States",
          "United Kingdom",
          "Canada"
        ],
        "cveIds": [
          "CVE-2019-11510",
          "CVE-2019-19781",
          "CVE-2018-13379"
        ],
        "summary": "Targeting of vaccine development organisations using WellMess and WellMail implants and exploitation of unpatched VPN appliances, disclosed in a joint advisory from the UK, U.S., and Canada during the height of the pandemic.",
        "sources": [
          {
            "org": "NCSC-UK / CSE / NSA / CISA",
            "title": "Advisory: APT29 targets COVID-19 vaccine development",
            "url": "https://www.ncsc.gov.uk/files/Advisory-APT29-targets-COVID-19-vaccine-development-V1-1.pdf",
            "date": "2020-07-16"
          }
        ]
      },
      {
        "id": "solarwinds",
        "actorId": "apt29",
        "name": "SolarWinds / SUNBURST Supply Chain Compromise",
        "date": "2019-09-04",
        "endDate": "2020-12-13",
        "significance": "landmark",
        "targetSectors": [
          "Government",
          "Technology",
          "Managed Service Providers",
          "Think Tanks & Academia",
          "Defense"
        ],
        "targetCountries": [
          "United States",
          "United Kingdom",
          "Canada",
          "Belgium",
          "Israel"
        ],
        "cveIds": [],
        "summary": "Compromise of the SolarWinds Orion build system, distributing the SUNBURST backdoor to roughly 18,000 customers, from which fewer than 100 were selected for follow-on exploitation. Victims included the U.S. Departments of Treasury, Commerce, Homeland Security, State, Energy, and Justice. The actor spent a month testing a benign code injection before shipping the real payload.",
        "sources": [
          {
            "org": "Mandiant / FireEye",
            "title": "Highly Evasive Attacker Leverages SolarWinds Supply Chain",
            "url": "https://cloud.google.com/blog/topics/threat-intelligence/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor",
            "date": "2020-12-13"
          },
          {
            "org": "CISA",
            "title": "AA20-352A: Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure",
            "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
            "date": "2020-12-17"
          }
        ]
      }
    ],
    "flag": "🇷🇺",
    "profile": "/apt/apt29/"
  }
}