MITRE ATT&CK G0016
Aliases: Cozy Bear, Nobelium, Midnight Blizzard, The Dukes, SVR
Official Attribution Source: CISA Advisory AA20-352A & White House Statement

Key Facts

Jurisdiction
Russian Federation
Geographic origin
Cases
2
Prosecution matters
Defendants
0
Indicted individuals
Sanctions
0
OFAC designations
  • Attributed Country: Russian Federation.
  • ATT&CK Group Reference: G0016 (APT29).
  • Linked to 2 primary court prosecution records.
  • Identified 0 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to APT29 Technique frequencies extracted from verified indictments for APT29. T1190 Exploit Public-Facing Application 1 incidents T1071.001 Web Protocols 1 incidents T1078 Valid Accounts 1 incidents T1132 Data Encoding 1 incidents T1036 Masquerading 1 incidents T1110 Brute Force 1 incidents T1041 Exfiltration Over C2 Channel 1 incidents
Technique frequencies extracted from verified indictments for APT29.
ATT&CK Techniques Mapped to APT29
Technique Frequency
T1190 Exploit Public-Facing Application 1 incidents
T1071.001 Web Protocols 1 incidents
T1078 Valid Accounts 1 incidents
T1132 Data Encoding 1 incidents
T1036 Masquerading 1 incidents
T1110 Brute Force 1 incidents
T1041 Exfiltration Over C2 Channel 1 incidents

Prosecution Cases Attributed to This Actor

alleged 2020-12-13

SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)

Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.

5 techniques View case →
investigation 2024-01-19

Microsoft Corporate Executive Email Intrusion (Midnight Blizzard / SVR)

Russian Foreign Intelligence Service (SVR / Midnight Blizzard / APT29) compromised Microsoft corporate email systems via a password spray campaign against a legacy non-production test tenant lacking multi-factor authentication. Attackers leveraged the test account's permissions to grant full OAuth app-level access, reading executive emails and exfiltrating source code and customer cryptographic secrets.

3 techniques View case →
OPERATIONAL DEFENSE

Targeted Defensive Hardening for APT29

Run Stack Audit →

Primary Initial Access Defense

Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.

Lateral Movement Interception

Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.