- Home
- APT groups
- APT29
APT group profile
APT29
Cyberespionage group attributed by the U.S. and the UK to Russia's Foreign Intelligence Service (SVR), active since at least 2008; responsible for the SolarWinds compromise and for persistent intrusions into cloud and identity environments.
Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.
Overview
APT29 is a cyberespionage actor that, according to MITRE ATT&CK, has operated since at least 2008 and has been attributed to Russia’s Foreign Intelligence Service (SVR). The U.S. government formalized that attribution in April 2021 in the wake of the SolarWinds compromise (CISA AA20-352A). Joint advisory AA24-057A describes it as “almost certainly part of the SVR”.
Its usual targets are foreign ministries, governments, diplomatic bodies, think tanks, NGOs, research centers and technology providers whose products or services give access to many customers. It stands out for its patience and operational discipline: it compromises the software supply chain, exploits exposed services and, in recent years, has directly attacked the cloud identity layer (Entra ID/Microsoft 365) with password spraying, malicious OAuth applications, token abuse and federation abuse. In LATAM, Microsoft documented victims in Mexico during the later stage of SolarWinds. There are no public reports of campaigns specifically targeting Colombia.
Notable campaigns
- 2019–2021 — SolarWinds supply chain compromise: trojanization of SolarWinds Orion updates with SUNBURST, followed by selective movement into cloud and identity environments (Mandiant, CISA AA20-352A). Microsoft identified victims in the U.S., Canada, Mexico, Belgium, Spain, the UK, Israel and the United Arab Emirates (Microsoft).
- 2023 — Exploitation of JetBrains TeamCity (CVE-2023-42793): access to development servers in the U.S., Europe, Asia and Australia, using the GraphicalProton backdoor and the BYOVD technique to disable EDR (CISA AA23-347A).
- 2023–2024 — Intrusion into Microsoft corporate email: password spraying against a test account without MFA, abuse of OAuth applications to obtain the
full_access_as_approle and use of residential proxies (Microsoft). - 2024 — Spearphishing with RDP files: emails targeting government, academia, defense and NGOs in dozens of countries, mainly the UK, Europe, Australia and Japan, with signed .rdp files that mapped local resources to actor-controlled servers (Microsoft).
- 2026 — CaptiveCrunch: DNS/HTTP manipulation of captive portals at hotels and conference centers to deliver the CornFlake and ChocoShell malware and conduct device code phishing against Entra ID. Microsoft attributes it to Storm-2945, a subgroup of Midnight Blizzard (Microsoft).
Key TTPs
Initial access. Software supply chain (T1195.002); spearphishing with links, often with HTML smuggling via EnvyScout (T1566.002, T1027.006), and delivery through legitimate mailing services such as Constant Contact (T1566.003). Low-volume password spraying (T1110.003), exploitation of exposed applications such as VPN, Citrix, Exchange and TeamCity (T1190), external remote services (T1133) and valid cloud accounts (T1078.004). It uses MFA fatigue (T1621) to defeat the second factor.
Execution and persistence. PowerShell (T1059.001), WMI event subscriptions (T1546.003) and scheduled tasks (T1053.005). In the cloud it adds credentials to service principals and applications (T1098.001), grants mailbox delegate permissions (T1098.002) and modifies authentication in AD FS (hybrid identity, T1556.007) and domain or tenant federation trust relationships (T1484.002).
Credentials and lateral movement. It forges SAML tokens (the “Golden SAML” technique, T1606.002), performs DCSync (T1003.006) and Kerberoasting (T1558.003), steals session cookies (T1539) and moves between cloud services (T1021.007).
Collection and C2. It extracts email via EWS/Graph (T1114.002). It conceals its infrastructure with residential proxies (T1665), domain fronting with Tor/meek (T1090.004) and legitimate web services for bidirectional C2 (T1102.002).
Detection and mitigation
- Cloud identity. Require phishing-resistant MFA (M1032) and disable or remove inactive and service accounts without MFA (M1018). Periodically review service principals with new credentials, OAuth consents and role assignments such as
full_access_as_appor ApplicationImpersonation in the Entra ID audit logs and the Unified Audit Log (AA24-057A). - Password spraying and residential proxies. Do not rely on IP reputation alone. Correlate authentication failures distributed across many accounts, sign-ins to test or legacy accounts and access from residential ASNs that are unusual for the organization.
- Federation and tokens. Protect AD FS and Entra Connect as Tier 0 assets. Alert on changes to federation configuration, token-signing certificates and trusted domains. Detect SAML tokens without a corresponding sign-in event (M1015, M1026).
- Device code and RDP. Use Conditional Access to block the device code flow where it is not needed. Block .rdp attachments at the email gateway and outbound RDP connections to the Internet (M1031, M1021).
- Endpoints and servers. Prioritize patching of exposed services (M1051). Hunt for unusual child processes of development and CI/CD servers, new WMI subscriptions (Sysmon EID 19–21), scheduled tasks created by service accounts and DRSUAPI replication requests made from hosts that are not domain controllers (DCSync).
- Travelers. For diplomatic and executive staff who travel, require an always-on VPN on public Wi-Fi and prohibit installing “updates” offered by captive portals, in line with the recommendations from Microsoft.
MITRE ATT&CK techniques
Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.
Initial Access
Execution
Persistence
Privilege Escalation
- T1484.002 Domain or Tenant Policy Modification: Trust Modification
Stealth
- T1027.006 Obfuscated Files or Information: HTML Smuggling
Credential Access
Lateral Movement
- T1021.007 Remote Services: Cloud Services
Collection
- T1114.002 Email Collection: Remote Email Collection
Malware and tools
Malware
References
Public sources this profile is based on.
- [1] APT29, Group G0016 · MITRE ATT&CK
- [2] Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations (AA20-352A) · CISA, Dec 2020
- [3] A moment of reckoning: the need for a strong and global cybersecurity response · Microsoft, Dec 2020
- [4] SolarWinds Supply Chain Attack Uses SUNBURST Backdoor · Mandiant (Google Cloud), Dec 2020
- [5] Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally (AA23-347A) · CISA, Dec 2023
- [6] Midnight Blizzard: Guidance for responders on nation-state attack · Microsoft Threat Intelligence, Jan 2024
- [7] SVR Cyber Actors Adapt Tactics for Initial Cloud Access (AA24-057A) · CISA / NCSC, Feb 2024
- [8] Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files · Microsoft Threat Intelligence, Oct 2024
- [9] CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft · Microsoft Threat Intelligence, Jul 2026
Profile last updated: