Skip to content
RussiaState-SponsoredActiveMITRE G0016Malpedia ↗

APT29

Russia's SVR foreign intelligence service. Executed the SolarWinds supply-chain compromise and remains the benchmark for patient, cloud-native espionage.

Open MITRE Navigator layer ↗Download profile JSON
Active
2008–present
Motivation
Espionage
Aliases
16
Exploited CVEs
6
ATT&CK techniques
16
Cited sources
15

Overview

APT29 belongs to the SVR, Russia's civilian foreign intelligence service — the institutional successor to the KGB's First Chief Directorate. It is the most operationally disciplined state actor tracked in the public record.

The group's defining characteristic is patience. Where APT28 burns infrastructure and accepts noise, APT29 will spend a year inside a network without triggering a single alert. The SolarWinds operation is the clearest expression of this: the actor compromised the build system in September 2019, spent a month testing a benign code injection to verify it would go unnoticed, and only then shipped the SUNBURST backdoor to some 18,000 downstream customers — from which it selected fewer than 100 for actual follow-on exploitation.

Since 2021 APT29 has pivoted decisively toward identity and cloud. Rather than dropping malware on endpoints, it targets the authentication layer directly: stolen OAuth application consent, forged SAML assertions via the Golden SAML technique, service-principal abuse in Microsoft Entra ID, residential-proxy networks to defeat impossible-travel detection, and password spraying against legacy accounts without MFA. Its January 2024 breach of Microsoft's own corporate email began with a password spray against a legacy non-production test tenant.

Targeting is strategic and narrow: foreign ministries, national security policy bodies, IT and cloud providers used as stepping stones, and — during 2020 — COVID-19 vaccine research at institutions in the U.S., UK, and Canada.

Attribution

Down to the named unit where public evidence supports it.

RussiaSVR — Foreign Intelligence ServiceConfirmed

Formally attributed to the SVR by the U.S. and UK governments in April 2021, concurrent with sanctions on Russia over the SolarWinds compromise. The U.S. Treasury designation, NSA/CISA/FBI joint advisory, and UK NCSC statement were issued the same day and name the SVR explicitly. Unlike the GRU groups, no individual SVR officers have been indicted, and no internal unit designator has been publicly established.

Attributing sources

Cross-vendor naming crosswalk

16 designators across 12 organisations.

3 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • APT29

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Midnight BlizzardFormerly NOBELIUM
  • NOBELIUMRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Cozy Bear

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT29
  • UNC2452partialThe SolarWinds intrusion cluster specifically; merged into APT29 in April 2022 after Mandiant assessed overlap

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • IRON RITUAL
  • IRON HEMLOCKpartialTracks a related but distinct subset of SVR activity

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Cloaked Ursa

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Recorded Future Insikt Group

index ↗
  • BlueBravo

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Red Canary

index ↗
  • Cozy BearAdopts the prevailing community designator

Names activity clusters descriptively rather than by a fixed nation-state taxonomy, and generally adopts the prevailing community name for established state actors. Coverage skews toward commodity and eCrime threats seen in managed-detection telemetry.

ESET Research

index ↗
  • The Dukes

Descriptive names, frequently derived from the group's flagship malware family.

Kaspersky GReAT

index ↗
  • The Dukes
  • CozyDukepartialRefers to a specific implant family within the Dukes toolset

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Trend Micro

index ↗
  • Earth Koshchei

'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.

CISA / NSA / FBI

index ↗
  • SVR

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesUnited KingdomGermanyNetherlandsNorwayCzechiaPolandCanadaItalyUkraine

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

SUNBURSTbackdoor

Trojanised SolarWinds Orion plugin. Dormant for 12–14 days after install, verified the victim domain against a blocklist before activating.

Malpedia ↗
TEARDROPloader

Memory-only dropper deployed by SUNBURST to load a customised Cobalt Strike Beacon.

Malpedia ↗
RAINDROPloader

Second-stage loader used for lateral movement in a subset of SolarWinds victims.

Malpedia ↗
FoggyWebbackdoor

Post-exploitation backdoor for AD FS servers that exfiltrates the token-signing certificate — enabling arbitrary token forgery.

Malpedia ↗
MagicWebbackdoor

Malicious AD FS DLL allowing authentication as any user by injecting a claim into the token issuance pipeline.

WINELOADERbackdoor

Modular backdoor delivered via wine-tasting-themed diplomatic lures across European foreign ministries.

Malpedia ↗
EnvyScoutloader

HTML smuggling dropper delivering an ISO or IMG container to bypass Mark-of-the-Web.

GoldMaxbackdoor

Go-based C2 backdoor masquerading as a scheduled system task, with an encrypted decoy traffic generator.

WellMessbackdoor

Cross-platform Go/.NET implant used against COVID-19 vaccine research organisations.

Malpedia ↗

Shared, commodity & living-off-the-land

Golden SAMLlotl

Forging SAML assertions with a stolen token-signing key to authenticate to cloud services as any user, bypassing MFA entirely.

Cobalt Strikeframework

Commercial C2 framework with heavily customised malleable profiles and watermark-stripped beacons.

AdFindlotl

Legitimate Active Directory query tool used for domain reconnaissance.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT29
CVE-2023-42793KEVransomware9.81 Sep 2023Mass exploitation of internet-facing JetBrains TeamCity servers to reach software build pipelines — the same strategic objective as SolarWinds, pursued opportunistically at scale. Prompted a joint advisory from five countries.SRCCISA / FBI / NSA / NCSC-UK / SKW-PL
CVE-2021-21972KEVransomware9.81 Mar 2021VMware vCenter unauthenticated RCE listed among SVR-exploited vulnerabilities for initial access.SRCNSA / CISA / FBI
CVE-2020-1472KEVransomware10.01 Oct 2020Zerologon used for domain escalation in intrusions following perimeter compromise.SRCCISA
CVE-2018-13379KEVransomware9.81 May 2020FortiOS SSL VPN path traversal used to obtain plaintext VPN credentials from unpatched appliances.SRCNSA / CISA / FBI
CVE-2019-11510KEVransomware10.01 Apr 2020Pulse Secure file read used to harvest VPN credentials during the COVID-19 vaccine research targeting campaign.SRCNCSC-UK / CSE / NSA / CISA
CVE-2019-19781KEVransomware9.81 Jan 2020Citrix ADC traversal exploited for initial access to enterprise perimeters.SRCNSA / CISA / FBI

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

8 stages · 16 techniques
  1. 01

    Initial Access

    3 techniques

    Enters through the identity layer or the software supply chain rather than the endpoint. Historically that meant compromising a build system — SolarWinds Orion — and shipping the backdoor to 18,000 customers. Since 2021 it more often means a low-and-slow password spray against a forgotten legacy tenant, or a signed RDP configuration file that a diplomat opens without alarm.

  2. 02

    Persistence

    1 technique

    Persists as configuration, not as malware. Credentials added to an existing service principal, or a consented OAuth application with mailbox scope, survive endpoint reimaging and password rotation because nothing on disk was ever the foothold.

  3. 04

    Defense Evasion

    4 techniques

    Optimises for never being investigated in the first place. SUNBURST slept twelve to fourteen days, checked the victim domain against a blocklist, and generated decoy traffic; operators cleared logs after each session and reused stolen code-signing certificates so payloads carried a valid signature.

  4. 06

    Lateral Movement

    1 technique

    Moves by authenticating, not by exploiting. A forged token or a stolen application access token is presented to the next service exactly as a legitimate user would present it, so lateral movement generates successful-login telemetry rather than intrusion telemetry.

  5. 07

    Collection

    1 technique

    Takes mail, selectively. Mailbox collection is scoped to the specific officials whose correspondence answers the intelligence requirement — in the January 2024 Microsoft breach, the security and legal functions and the senior leadership team.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
16 techniques across 8 tactics · 14 with actor-specific notes

Initial Access

3

Persistence

1

Privilege Escalation

1

Credential Access

3

Lateral Movement

1

Command and Control

2

Campaign timeline

  1. Microsoft Corporate Email Breach

    Password spray against a legacy non-production test tenant without MFA, escalated via an OAuth application with elevated access to Microsoft corporate mailboxes — including members of the senior leadership team and the security and legal functions. Source code repositories were also accessed.

    TechnologyGovernment
  2. COVID-19 Vaccine Research Targeting

    Targeting of vaccine development organisations using WellMess and WellMail implants and exploitation of unpatched VPN appliances, disclosed in a joint advisory from the UK, U.S., and Canada during the height of the pandemic.

    CVE-2019-11510CVE-2019-19781CVE-2018-13379HealthcarePharmaceuticalsThink Tanks & Academia
  3. landmark

    SolarWinds / SUNBURST Supply Chain Compromise

    Compromise of the SolarWinds Orion build system, distributing the SUNBURST backdoor to roughly 18,000 customers, from which fewer than 100 were selected for follow-on exploitation. Victims included the U.S. Departments of Treasury, Commerce, Homeland Security, State, Energy, and Justice. The actor spent a month testing a benign code injection before shipping the real payload.

    GovernmentTechnologyManaged Service ProvidersThink Tanks & Academia

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.