Skip to content

APT group profile

APT29

Cyberespionage group attributed by the U.S. and the UK to Russia's Foreign Intelligence Service (SVR), active since at least 2008; responsible for the SolarWinds compromise and for persistent intrusions into cloud and identity environments.

MITRE G0016 Espionage LATAM Updated

Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.

MITRE ATT&CK techniques

Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.

Initial Access

  • T1078.004 Valid Accounts: Cloud Accounts
  • T1133 External Remote Services
  • T1190 Exploit Public-Facing Application
  • T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
  • T1566.002 Phishing: Spearphishing Link
  • T1566.003 Phishing: Spearphishing via Service

Execution

  • T1053.005 Scheduled Task/Job: Scheduled Task
  • T1059.001 Command and Scripting Interpreter: PowerShell

Persistence

  • T1098.001 Account Manipulation: Additional Cloud Credentials
  • T1098.002 Account Manipulation: Additional Email Delegate Permissions
  • T1546.003 Event Triggered Execution: Windows Management Instrumentation Event Subscription
  • T1556.007 Modify Authentication Process: Hybrid Identity

Privilege Escalation

  • T1484.002 Domain or Tenant Policy Modification: Trust Modification

Stealth

  • T1027.006 Obfuscated Files or Information: HTML Smuggling

Credential Access

  • T1003.006 OS Credential Dumping: DCSync
  • T1110.003 Brute Force: Password Spraying
  • T1539 Steal Web Session Cookie
  • T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting
  • T1606.002 Forge Web Credentials: SAML Tokens
  • T1621 Multi-Factor Authentication Request Generation

Lateral Movement

Collection

  • T1114.002 Email Collection: Remote Email Collection

Command and Control

Malware and tools

References

Public sources this profile is based on.

  1. [1] APT29, Group G0016 · MITRE ATT&CK
  2. [2] Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations (AA20-352A) · CISA, Dec 2020
  3. [3] A moment of reckoning: the need for a strong and global cybersecurity response · Microsoft, Dec 2020
  4. [4] SolarWinds Supply Chain Attack Uses SUNBURST Backdoor · Mandiant (Google Cloud), Dec 2020
  5. [5] Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally (AA23-347A) · CISA, Dec 2023
  6. [6] Midnight Blizzard: Guidance for responders on nation-state attack · Microsoft Threat Intelligence, Jan 2024
  7. [7] SVR Cyber Actors Adapt Tactics for Initial Cloud Access (AA24-057A) · CISA / NCSC, Feb 2024
  8. [8] Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files · Microsoft Threat Intelligence, Oct 2024
  9. [9] CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft · Microsoft Threat Intelligence, Jul 2026

Profile last updated:

Concerned about this group?

The Ventura Systems MDR service monitors the techniques of this and other actors 24/7, with ATT&CK-based threat hunting.