Skip to main content
QUIETLYTIC
Threat Actor

APT29

Threat group attributed by MITRE ATT&CK to Russia's Foreign Intelligence Service (SVR), active since at least 2008 and linked to the 2015-16 DNC compromise and the 2020 SolarWinds supply-chain attack.

Threat Level
CRITICAL
Attribution
Russian Foreign Intelligence Service (SVR) — per US and UK government attribution cited in MITRE ATT&CK's group profile
Also Known As
IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard
Targets
Government networks in Europe and NATO member countries, Research institutes and think tanks, Democratic National Committee (2015-16)

Overview

APT29 (MITRE ATT&CK ID G0016) is a threat group MITRE ATT&CK attributes to Russia’s Foreign Intelligence Service (SVR), citing formal April 2021 statements from the White House and UK government. Per MITRE’s profile, the group has operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks — and reportedly compromised the Democratic National Committee starting in summer 2015.

In April 2021, per MITRE’s documentation, the US and UK governments formally attributed the SolarWinds Compromise to the SVR, with public statements citing APT29, Cozy Bear, and The Dukes as associated designations. Industry reporting cited in MITRE’s profile also refers to the actors involved in that campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.

Known tools and malware (per MITRE ATT&CK relationship data)

Our ingested data links APT29 to an unusually large documented toolset, including the SUNBURST and TEARDROP malware from the SolarWinds campaign, SUNSPOT, GoldMax, FoggyWeb, HAMMERTOSS, WellMess, WellMail, Cobalt Strike, Mimikatz, and a long-running “Duke” malware family lineage (MiniDuke, CosmicDuke, CozyCar, SeaDuke, PolyglotDuke, RegDuke, FatDuke, LiteDuke, PinchDuke, GeminiDuke, OnionDuke, CloudDuke).

Notable techniques (per MITRE ATT&CK relationship data)

Techniques linked to APT29 in our data include Accessibility Features (T1546.008), Additional Email Delegate Permissions (T1098.002), Binary Padding (T1027.001), Boot or Logon Initialization Scripts (T1037), Bypass User Account Control (T1548.002), and Cloud API (T1059.009) and Cloud Account (T1136.003 / T1087.004) — reflecting the cloud/identity-focused tradecraft documented in the SolarWinds-era campaigns.

Per MITRE ATT&CK’s relationship data, APT29 is linked to Operation Ghost and the SolarWinds Compromise, the supply-chain operation formally attributed to the SVR by the US and UK governments in April 2021.

What we don’t have

MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2008” per MITRE’s description text. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.

Frequently Asked Questions

What is APT29? A threat group attributed by the US and UK governments (per MITRE ATT&CK’s citations) to Russia’s Foreign Intelligence Service (SVR), active since at least 2008.

Is APT29 the same as Cozy Bear or NOBELIUM? Yes — MITRE ATT&CK tracks these as aliases of the same group designation, alongside Dark Halo, UNC2452, and several others used across different vendors’ reporting.

Was APT29 responsible for the SolarWinds attack? Per MITRE ATT&CK’s citations of formal April 2021 US and UK government statements, yes — the SolarWinds Compromise was attributed to the SVR, associated with the APT29/Cozy Bear/The Dukes designation.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0016, aggregated September 8, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools