Saltar al contenido

Perfil de grupo APT

APT29

Grupo de ciberespionaje atribuido por EE. UU. y Reino Unido al Servicio de Inteligencia Exterior ruso (SVR), activo desde al menos 2008; responsable del compromiso de SolarWinds y de intrusiones persistentes en entornos cloud e identidad.

MITRE G0016 Espionaje Actualizado

Técnicas MITRE ATT&CK

Técnicas atribuidas al grupo en fuentes públicas, agrupadas por táctica. Cada ID enlaza a attack.mitre.org.

Acceso inicial

  • T1078.004 Valid Accounts: Cloud Accounts
  • T1133 External Remote Services
  • T1190 Exploit Public-Facing Application
  • T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
  • T1566.002 Phishing: Spearphishing Link
  • T1566.003 Phishing: Spearphishing via Service

Ejecución

  • T1053.005 Scheduled Task/Job: Scheduled Task
  • T1059.001 Command and Scripting Interpreter: PowerShell

Persistencia

  • T1098.001 Account Manipulation: Additional Cloud Credentials
  • T1098.002 Account Manipulation: Additional Email Delegate Permissions
  • T1546.003 Event Triggered Execution: Windows Management Instrumentation Event Subscription
  • T1556.007 Modify Authentication Process: Hybrid Identity

Escalamiento de privilegios

  • T1484.002 Domain or Tenant Policy Modification: Trust Modification

Sigilo

  • T1027.006 Obfuscated Files or Information: HTML Smuggling

Acceso a credenciales

  • T1003.006 OS Credential Dumping: DCSync
  • T1110.003 Brute Force: Password Spraying
  • T1539 Steal Web Session Cookie
  • T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting
  • T1606.002 Forge Web Credentials: SAML Tokens
  • T1621 Multi-Factor Authentication Request Generation

Movimiento lateral

Recolección

  • T1114.002 Email Collection: Remote Email Collection

Comando y control

Malware y herramientas

Referencias

Fuentes públicas en las que se basa este perfil.

  1. [1] APT29, Group G0016 · MITRE ATT&CK
  2. [2] Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations (AA20-352A) · CISA, dic. 2020
  3. [3] A moment of reckoning: the need for a strong and global cybersecurity response · Microsoft, dic. 2020
  4. [4] SolarWinds Supply Chain Attack Uses SUNBURST Backdoor · Mandiant (Google Cloud), dic. 2020
  5. [5] Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally (AA23-347A) · CISA, dic. 2023
  6. [6] Midnight Blizzard: Guidance for responders on nation-state attack · Microsoft Threat Intelligence, ene. 2024
  7. [7] SVR Cyber Actors Adapt Tactics for Initial Cloud Access (AA24-057A) · CISA / NCSC, feb. 2024
  8. [8] Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files · Microsoft Threat Intelligence, oct. 2024
  9. [9] CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft · Microsoft Threat Intelligence, jul. 2026

Última actualización del perfil:

¿Le preocupa este grupo?

El servicio MDR de Ventura Systems monitorea 24/7 las técnicas de este y otros actores, con caza de amenazas basada en ATT&CK.