created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false
APT29
APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G0016 |
| Aliases | IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard |
| Attribution | Russia |
| Class | state |
| Active since | — |
| ATT&CK entry created | 2017-05-31 |
| Techniques mapped | 115 |
Attribution — as claimed
Stated by MITRE ATT&CK (state attribution).
Known TTPs
| Technique | Name |
|---|---|
T1003.002 |
Security Account Manager |
T1003.004 |
LSA Secrets |
T1005 |
Data from Local System |
T1016.001 |
Internet Connection Discovery |
T1021.007 |
Cloud Services |
T1027.001 |
Binary Padding |
T1027.002 |
Software Packing |
T1027.006 |
HTML Smuggling |
T1036.005 |
Match Legitimate Resource Name or Location |
T1037 |
Boot or Logon Initialization Scripts |
T1037.004 |
RC Scripts |
T1047 |
Windows Management Instrumentation |
(First 12 of 115 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Apt28 — Russia-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G0016 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.