Key Facts
- Attributed Country: Russian Federation.
- ATT&CK Group Reference: G0016 (APT29).
- Linked to 2 primary court prosecution records.
- Identified 0 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1190 Exploit Public-Facing Application | 1 incidents |
| T1071.001 Web Protocols | 1 incidents |
| T1078 Valid Accounts | 1 incidents |
| T1132 Data Encoding | 1 incidents |
| T1036 Masquerading | 1 incidents |
| T1110 Brute Force | 1 incidents |
| T1041 Exfiltration Over C2 Channel | 1 incidents |
Prosecution Cases Attributed to This Actor
SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)
Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.
Microsoft Corporate Executive Email Intrusion (Midnight Blizzard / SVR)
Russian Foreign Intelligence Service (SVR / Midnight Blizzard / APT29) compromised Microsoft corporate email systems via a password spray campaign against a legacy non-production test tenant lacking multi-factor authentication. Attackers leveraged the test account's permissions to grant full OAuth app-level access, reading executive emails and exfiltrating source code and customer cryptographic secrets.
Targeted Defensive Hardening for APT29
Primary Initial Access Defense
Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.
Lateral Movement Interception
Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.