Overview
APT29 (MITRE ATT&CK ID G0016) is a threat group MITRE ATT&CK attributes to Russia’s Foreign Intelligence Service (SVR), citing formal April 2021 statements from the White House and UK government. Per MITRE’s profile, the group has operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks — and reportedly compromised the Democratic National Committee starting in summer 2015.
In April 2021, per MITRE’s documentation, the US and UK governments formally attributed the SolarWinds Compromise to the SVR, with public statements citing APT29, Cozy Bear, and The Dukes as associated designations. Industry reporting cited in MITRE’s profile also refers to the actors involved in that campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.
Known tools and malware (per MITRE ATT&CK relationship data)
Our ingested data links APT29 to an unusually large documented toolset, including the SUNBURST and TEARDROP malware from the SolarWinds campaign, SUNSPOT, GoldMax, FoggyWeb, HAMMERTOSS, WellMess, WellMail, Cobalt Strike, Mimikatz, and a long-running “Duke” malware family lineage (MiniDuke, CosmicDuke, CozyCar, SeaDuke, PolyglotDuke, RegDuke, FatDuke, LiteDuke, PinchDuke, GeminiDuke, OnionDuke, CloudDuke).
Notable techniques (per MITRE ATT&CK relationship data)
Techniques linked to APT29 in our data include Accessibility Features (T1546.008), Additional Email Delegate Permissions (T1098.002), Binary Padding (T1027.001), Boot or Logon Initialization Scripts (T1037), Bypass User Account Control (T1548.002), and Cloud API (T1059.009) and Cloud Account (T1136.003 / T1087.004) — reflecting the cloud/identity-focused tradecraft documented in the SolarWinds-era campaigns.
Related campaigns
Per MITRE ATT&CK’s relationship data, APT29 is linked to Operation Ghost and the SolarWinds Compromise, the supply-chain operation formally attributed to the SVR by the US and UK governments in April 2021.
What we don’t have
MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2008” per MITRE’s description text. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.
Frequently Asked Questions
What is APT29? A threat group attributed by the US and UK governments (per MITRE ATT&CK’s citations) to Russia’s Foreign Intelligence Service (SVR), active since at least 2008.
Is APT29 the same as Cozy Bear or NOBELIUM? Yes — MITRE ATT&CK tracks these as aliases of the same group designation, alongside Dark Halo, UNC2452, and several others used across different vendors’ reporting.
Was APT29 responsible for the SolarWinds attack? Per MITRE ATT&CK’s citations of formal April 2021 US and UK government statements, yes — the SolarWinds Compromise was attributed to the SVR, associated with the APT29/Cozy Bear/The Dukes designation.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0016, aggregated September 8, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.