Cyber overview
Cyber threat actor

APT29

Russian Foreign Intelligence Service (SVR) · active since 2008

SVR-attributed espionage group behind the SolarWinds supply-chain compromise and sustained targeting of US government, think-tank and cloud-provider networks.

Aliases
Midnight BlizzardCozy BearNOBELIUMThe Dukes
Primary targets
US federal agencies Cloud/SaaS providers Think tanks Diplomatic missions

MITRE ATT&CK techniques

0 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.

No MITRE ATT&CK mapping available yet for APT29.

Curated incidents

  1. 2020-12-13·Government / IT·United States
    SolarWinds Orion supply-chain compromise attributed to APT29

    SVR-linked actors trojanized Orion software updates, compromising nine federal agencies and dozens of private companies.