All actors

APT29

Also reported as UNC2452, Midnight Blizzard, NOBELIUM, The Dukes, UNC3524 and 37 other names. Linked to Russia by four sources.

Reports
1,179
Last reported
Known CVEs
440
Techniques in ATT&CK
66
Origin
Russia
ID
G0016
Merge evidence
71 alias matches

Reports per quarter

  1. 2014 Q3: 1 report
  2. 2014 Q4: 2 reports
  3. 2015 Q1: no reports
  4. 2015 Q2: 2 reports
  5. 2015 Q3: 16 reports
  6. 2015 Q4: 1 report
  7. 2016 Q1: 3 reports
  8. 2016 Q2: 6 reports
  9. 2016 Q3: 3 reports
  10. 2016 Q4: 4 reports
  11. 2017 Q1: 9 reports
  12. 2017 Q2: 9 reports
  13. 2017 Q3: no reports
  14. 2017 Q4: 1 report
  15. 2018 Q1: 1 report
  16. 2018 Q2: 3 reports
  17. 2018 Q3: 4 reports
  18. 2018 Q4: 10 reports
  19. 2019 Q1: 6 reports
  20. 2019 Q2: 11 reports
  21. 2019 Q3: 3 reports
  22. 2019 Q4: 10 reports
  23. 2020 Q1: 8 reports
  24. 2020 Q2: 17 reports
  25. 2020 Q3: 34 reports
  26. 2020 Q4: 126 reports
  27. 2021 Q1: 108 reports
  28. 2021 Q2: 98 reports
  29. 2021 Q3: 84 reports
  30. 2021 Q4: 68 reports
  31. 2022 Q1: 73 reports
  32. 2022 Q2: 92 reports
  33. 2022 Q3: 73 reports
  34. 2022 Q4: 20 reports
  35. 2023 Q1: 29 reports
  36. 2023 Q2: 19 reports
  37. 2023 Q3: 23 reports
  38. 2023 Q4: 20 reports
  39. 2024 Q1: 15 reports
  40. 2024 Q2: 17 reports
  41. 2024 Q3: 25 reports
  42. 2024 Q4: 14 reports
  43. 2025 Q1: 7 reports
  44. 2025 Q2: 10 reports
  45. 2025 Q3: 8 reports
  46. 2025 Q4: 6 reports
  47. 2026 Q1: 6 reports
  48. 2026 Q2: 72 reports
  49. 2026 Q3: 2 reports
Dated reports, 2014 Q3 to 2026 Q3.

Techniques seen in the last two years

Show all 311 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 13 techniques Show fewer

CVEs named in reports

Show all 440 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Cozy Bear

    date ORKL added it fromORKL

  2. TEARDROP (Malware Family)

    date ORKL added it fromORKL

Show all 1,179 reports Show fewer
  1. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  2. APT 29, Cozy Bear, The Dukes

    date ORKL added it fromORKL

  3. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  4. APT 29, Cozy Bear, The Dukes

    date ORKL added it fromORKL

  5. elf.wellmess (Malware Family)

    date ORKL added it fromORKL

  6. SUNBURST (Malware Family)

    date ORKL added it fromORKL

  7. APT 29, Cozy Bear, The Dukes

    date ORKL added it fromORKL

  8. GoldMax (Malware Family)

    date ORKL added it fromORKL

  9. No Easy Breach DerbyCon 2016

    date ORKL added it fromORKL

  10. No Easy Breach DerbyCon 2016

    date ORKL added it fromORKL

  11. Cobalt Strike (Malware Family)

    date ORKL added it fromORKL

  12. BONDUPDATER (Malware Family)

    date ORKL added it fromORKL

  13. Sofacy, APT 28, Fancy Bear, Sednit

    date ORKL added it fromORKL

  14. BlackSuit Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  15. Binary Defense

    Malpedia library date fromORKL

  16. APT29 attacks Embassies using CVE-2023-38831 - report en

    date in the CCS '25 data RSA fromCCS '25 data

  17. Unleashing the Power of Shimcache with Chainsaw

    date in the title fromORKL

  18. Tomiris called, they want their Turla malware back

    date in the title fromORKL

  19. Espionage campaign linked to Russian intelligence services

    date in the title fromORKL

  20. Analysis of APT29's attack activities against Italy

    date in the title fromORKL

  21. BumbleBee: Round Two

    publisher's date The DFIR Report fromORKLDFIR Report

  22. RedSense

    Malpedia library date fromORKL

  23. CosmicDuke Malware Analysis Report

    date in the title fromORKL

  24. A Cyber Threat Intelligence Self-Study Plan- Part 2

    date in the title fromORKL

  25. SUNSPOT Malware A Technical Analysis

    file creation date fromORKL

  26. PART 3- How I Met Your Beacon – Brute Ratel

    date in the title fromORKL

  27. PowerPoint Presentation

    file creation date fromORKL

  28. Space Invaders- Cyber Threats That Are Out Of This World

    date in the title fromORKL

  29. RedSense

    Malpedia library date fromORKL

  30. Abused Slack Service Analysis of APT29's Attack on Italy

    date in the CCS '25 data Freebuf fromCCS '25 data

  31. CERT-UA

    Malpedia library date fromORKL

  32. Analyzing a Brute Ratel Badger

    date in the title fromORKL

  33. CERT-UA

    Malpedia library date fromORKL

  34. Overview of Russian GRU and SVR Cyberespionage Campaigns 1H 2022

    date in the CCS '25 data Bushido Token fromORKLCCS '25 data

  35. RedSense

    Malpedia library date fromORKL

  36. 2020-12 - Solarwinds Breach Resource Center

    file creation date fromORKL

  37. Gamaredon Group Understanding the Russian APT

    date in the title fromORKL

  38. Russian cyber attack campaigns and actors.pdf

    file creation date fromORKL

  39. UNC3524: Eye Spy on Your Email

    file creation date Mandiant fromORKL

  40. UNC3524- Eye Spy on Your Email

    date in the title fromORKL

  41. UNC3524_ Eye Spy on Your Email _ Mandiant

    date in the CCS '25 data Mandiant fromORKLCCS '25 data

  42. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  43. yir-cyber-threats-report-download.pdf

    Malpedia library date fromORKL

  44. Quantum Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  45. Russian State-Sponsored and Criminal Cyber .pdf

    file creation date fromORKL

  46. Nobelium - Israeli Embassy Maldoc

    date in the CCS '25 data Inquest fromORKLCCS '25 data

  47. Nobelium - Israeli Embassy Maldoc

    date in the title fromORKL

  48. RedSense

    Malpedia library date fromORKL

  49. Conti Leaks- Examining the Panama Papers of Ransomware

    date in the title fromORKL

  50. CERT-UA

    Malpedia library date fromORKL

  51. 2021 Year In Review

    publisher's date The DFIR Report fromORKLDFIR Report

  52. 2021trends.pdf

    Malpedia library date fromORKL

  53. Nobelium Returns to the Political World Stage

    date in the title fromORKL

  54. Nobelium Returns to the Political World Stage

    date in the CCS '25 data Fortinet fromORKLCCS '25 data

  55. RedSense

    Malpedia library date fromORKL

  56. Observations from the StellarParticle Campaign

    file creation date crowdstrike fromORKL

  57. Report2022GTR

    file creation date fromORKL

  58. eset_threat_report_t32021

    file creation date fromORKL

  59. APT29_StellarParticle-Campaing_CrowdStrike

    date in the CCS '25 data CrowdStrike fromORKLCCS '25 data

  60. Anticipating Cyber Threats as the Ukraine Crisis Escalates

    date in the title fromORKL

  61. Patchwork APT caught in its own web

    date in the title fromORKL

  62. Phishing campaigns by the Nobelium intrusion set

    date in the title fromORKL

  63. FINDING BEACONS IN THE DARK 1650728751599

    Malpedia library date BlackBerry fromORKLCCS '25 data

  64. Technical report Armagedon

    Malpedia library date CrowdStrike fromORKLCCS '25 data

  65. From Zero to Domain Admin

    publisher's date The DFIR Report fromORKLDFIR Report

  66. APT trends report Q3 2021

    date in the title fromORKL

  67. New activity from Russian actor Nobelium

    date in the title fromORKL

  68. The layered infrastructure operated by APT29

    date in the title fromORKL

  69. Global_APT_Research_Report_for_the_first_half_of_2021-360

    file creation date fromORKL

  70. RedSense

    Malpedia library date fromORKL

  71. Zircolite vs Defense Evasion & Nobellium FoggyWeb

    date in the title fromORKL

  72. eset_threat_report_t22021

    file creation date fromORKL

  73. Microsoft Digital Defense Report OCTOBER 2021

    file creation date fromORKL

  74. APT_trends_report_Q2_2021_Securelist

    file creation date fromORKL

  75. Cobalt Strike, a Defender’s Guide

    date in the title fromORKL

  76. Cobalt Strike- Detect this Persistent Threat

    date in the title fromORKL

  77. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  78. Ryuk Ransomware Now Targeting Webservers

    Malpedia library date fromORKL

  79. Cobalt Strike- Favorite Tool from APT to Crimeware

    date in the title fromORKL

  80. New Nobelium activity

    date in the title fromORKL

  81. Russian hackers breached Dutch police systems in 2017

    date in the title fromORKL

  82. New sophisticated email-based attack from NOBELIUM

    date in the title fromORKL

  83. Defend and deter

    date in the title fromORKL

  84. Breaking down NOBELIUM’s latest early-stage toolset

    date in the title fromORKL

  85. Another Nobelium Cyberattack

    date in the title fromORKL

  86. New sophisticated email-based attack from NOBELIUM - Microsoft Security

    date in the CCS '25 data Microsoft fromORKLCCS '25 data

  87. Elizabethan England has nothing on modern-day Russia

    date in the title fromORKL

  88. Conti Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  89. Advisory Further TTPs associated with SVR cyber actors

    Malpedia library date NCSC fromORKLCCS '25 data

  90. CTIR_casestudy_2.pdf

    file creation date fromORKL

  91. CTIR_casestudy_1.pdf

    file creation date fromORKL

  92. the-operations-of-winnti-group.pdf

    Malpedia library date fromORKL

  93. SVR snaps back at Biden

    date in the title fromORKL

  94. Malware Analysis Report (AR21-105A)- SUNSHUTTLE

    date in the title fromORKL

  95. Statement on SolarWinds Cyber Compromise

    date in the title fromORKL

  96. mtrends-2021

    file creation date fromORKL

  97. 2021-Threat-Detection-Report

    file creation date fromORKL

  98. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  99. SilverFish_TLPWHITE

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  100. wp-m-unc2452.pdf

    file creation date fromORKL

  101. Technical Analysis of Operation Diànxùn

    Malpedia library date fromORKL

  102. Monitoring the Software Supply Chain with Azure Sentinel

    date in the title fromORKL

  103. Bazar Drops the Anchor

    publisher's date The DFIR Report fromORKLDFIR Report

  104. Intezer-2020-Go-Malware-Round-Up.pdf

    Malpedia library date fromORKL

  105. File not found · github/codeql

    Malpedia library date fromORKL

  106. The_CrowdStrike_2021_Global_Threat_Report

    file creation date fromORKL

  107. Bazar, No Ryuk?

    publisher's date The DFIR Report fromORKLDFIR Report

  108. Cloudy with a Chance of Persistent Email Access

    date in the title fromORKL

  109. Mimecast links security breach to SolarWinds hackers

    date in the title fromORKL

  110. Mandiant Azure AD Investigator- Focusing on UNC2452 TTPs

    date in the title fromORKL

  111. The Devil’s in the Details- SUNBURST Attribution

    date in the title fromORKL

  112. UNC2452- What We Know So Far

    date in the title fromORKL

  113. crowdstrike.com-SUNSPOT An Implant in the Build Process

    date in the CCS '25 data CrowdStrike fromORKLCCS '25 data

  114. Sunburst backdoor – code overlaps with Kazuar

    date in the title fromORKL

  115. SUNSPOT- An Implant in the Build Process

    date in the title fromORKL

  116. securelist.com-Sunburst backdoor code overlaps with Kazuar

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  117. Robust Indicators of Compromise for SUNBURST

    date in the title fromORKL

  118. Supply Chain Compromise

    date in the title fromORKL

  119. Finding Targeted SUNBURST Victims with pDNS

    date in the title fromORKL

  120. Golden SAML Revisited- The Solorigate Connection

    date in the title fromORKL

  121. Using Microsoft 365 Defender to protect against Solorigate

    date in the title fromORKL

  122. SUNBURST & Memory Analysis

    Malpedia library date fromORKL

  123. SUNBURST Additional Technical Details

    date in the title fromORKL

  124. SolarStorm Supply Chain Attack Timeline

    Malpedia library date fromORKL

  125. SolarStorm Supply Chain Attack Timeline

    date in the title fromORKL

  126. Identifying UNC2452-Related Techniques for ATT&CK

    date in the title fromORKL

  127. Top Linux Cloud Threats of 2020

    date in the title fromORKL

  128. Russian cyber attack campaigns and actors

    date in the title fromORKL

  129. Solorigate Resource Center

    date in the title fromORKL

  130. High Value Malicious Domains.

    date in the title fromORKL

  131. Sunburst- connecting the dots in the DNS requests

    date in the title fromORKL

  132. The Strategic Implications of SolarWinds

    date in the title fromORKL

  133. SUPERNOVA: A Novel .NET Webshell

    Malpedia library date fromORKL

  134. SUPERNOVA- SolarStorm’s Novel .NET Webshell

    date in the title fromORKL

  135. The SolarWinds Orion SUNBURST supply-chain Attack

    date in the title fromORKL

  136. SUPERNOVA SolarWinds .NET Webshell Analysis

    date in the title fromORKL

  137. Intel 471

    Malpedia library date fromORKL

  138. Threat Brief SolarStorm and SUNBURST Customer Coverage

    date in the title fromORKL

  139. Trojan-MSIL-Solorigate.B!dha

    date in the title fromORKL

  140. SUNBURST Countermeasures

    date in the title fromORKL

  141. Advanced Persistent Infrastructure Tracking

    date in the title fromORKL

  142. Genetic Analysis of CryptoWall Ransomware

    date in the title fromORKL

  143. APT_trends_report_Q3_2020_Securelist

    file creation date fromORKL

  144. The Enigmatic Energetic Bear

    date in the title fromORKL

  145. APT trends report Q3 2020

    date in the title fromORKL

  146. Ryuk in 5 Hours

    publisher's date The DFIR Report fromORKLDFIR Report

  147. Ryuk's Return

    publisher's date The DFIR Report fromORKLDFIR Report

  148. FY20 Microsoft Digital Defense Report

    Malpedia library date fromORKL

  149. Insights

    Malpedia library date fromORKL

  150. An overview of targeted attacks and APTs on Linux

    date in the title fromORKL

  151. Attribution- A Puzzle

    date in the title fromORKL

  152. US, UK, and Canada’s COVID-19 research targeted by APT29

    date in the title fromORKL

  153. Malware Analysis Report (AR20-198C)

    date in the title fromORKL

  154. Malware Analysis Report (AR20-198A)

    date in the title fromORKL

  155. Malware Analysis Report (AR20-198B)

    date in the title fromORKL

  156. Advisory-APT29-targets-COVID-19-vaccine-development

    Malpedia library date NCSC fromORKLCCS '25 data

  157. Intel 471

    Malpedia library date fromORKL

  158. Russian Cyber Attack Campaigns and Actors - Threat Research

    file creation date fromORKL

  159. Looking Back at LiteDuke

    date in the title fromORKL

  160. Ursnif via LOLbins

    publisher's date The DFIR Report fromORKLDFIR Report

  161. Catching APT41 exploiting a zero-day vulnerability

    date in the CCS '25 data Darktrace fromCCS '25 data

  162. 2020.02.22_APT_threat_report_2019_CN_version

    Malpedia library date fromORKL

  163. Group-IB_Hi-Tech_Crime_Trends_2019-2020_en

    file creation date fromORKL

  164. Group-IB_Hi-Tech_Crime_Trends_2019-2020

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  165. Aarhus_miniseminar_291118.pdf

    Malpedia library date fromORKL

  166. Operation Ghost

    Malpedia library date ESET fromORKLCCS '25 data

  167. LNKR- More than Just a Browser Extension

    date in the title fromORKL

  168. Mapping the connections inside Russia APT Ecosystem

    file creation date fromORKL

  169. APT-Attacks-eng.pdf

    file creation date fromORKL

  170. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date ThaiCERT fromORKL

  171. Hunting and detecting Cobalt Strike

    date in the title fromORKL

  172. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date Martijn van der Heide fromORKL

  173. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  174. 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version

    file creation date fromORKL

  175. 2018 APT Summary Report CN version

    file creation date fromORKL

  176. 2018 Master Table

    file creation date fromORKL

  177. CozyBear – In from the Cold-

    date in the title fromORKL

  178. Remember Fancy Bear-

    date in the title fromORKL

  179. M-Trends Overview

    Malpedia library date Marco Rottigni fromORKL

  180. A Slice of 2017 Sofacy Activity - Securelist

    date in the CCS '25 data NATO fromORKLCCS '25 data

  181. russian-federation-country-profile.pdf

    Malpedia library date fromORKL

  182. APT29

    date in the title fromORKL

  183. Snake- Coming soon in Mac OS X flavour

    date in the title fromORKL

  184. POSHSPY backdoor code

    date in the title fromORKL

  185. APT29 Domain Fronting With TOR

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  186. Enhanced Analysis of GRIZZLY STEPPE Activity

    file creation date US-CERT fromORKL

  187. [tr1adx]_ Intel

    date in the CCS '25 data tr1adx fromORKLCCS '25 data

  188. GRIZZLY STEPPE - Russian Malicious Cyber Activity

    date in the CCS '25 data US-CERT fromORKLCCS '25 data

  189. Running for Office_ Russian APT Toolkits Revealed

    file creation date fromORKL

  190. Please Read

    date in the CCS '25 data FireEye and Microsoft fromORKLCCS '25 data

  191. Findings from Analysis of DNC Intrusion Malware

    file creation date Fidelis fromORKL

  192. Bears in the Midst: Intrusion into the Democratic National Committee

    date in the CCS '25 data Crowdstrike fromORKLCCS '25 data

  193. PowerPoint Presentation

    date in the CCS '25 data CrowdStrike fromORKLCCS '25 data

  194. rpt-mtrends-2016.pdf

    file creation date fromORKL

  195. The Dukes- 7 Years Of Russian Cyber-Espionage

    date in the title fromORKL

  196. The Dukes: 7 years of Russian cyberespionage

    file creation date F-Secure fromORKL

  197. Fancy Bear

    date in the title fromORKL

  198. Fancy Bear

    Malpedia library date fromORKL

  199. Fancy Bear

    Malpedia library date fromORKL

  200. Hammertoss: Stealthy Tactics Define A Russian Cyber Threat Group

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  201. "Forkmeiamfamous": Seaduke, latest weapon in the Duke armory

    date in the CCS '25 data Symantec fromORKLCCS '25 data

  202. rpt-apt29-hammertoss.pdf

    Malpedia library date fromORKL

  203. CozyDuke: Malware Analysis

    date in the CCS '25 data F-Secure fromORKLCCS '25 data

  204. The Cozyduke APT

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  205. OnionDuke APT Attacks Via the Tor Network

    date in the CCS '25 data F-Secure fromCCS '25 data

Newest first. Details opens the report in Explore.