Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false

APT29

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks.

Attribute Detail
ATT&CK ID G0016
Aliases IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard
Attribution Russia
Class state
Active since
ATT&CK entry created 2017-05-31
Techniques mapped 115

Attribution — as claimed

Stated by MITRE ATT&CK (state attribution).

Known TTPs

Technique Name
T1003.002 Security Account Manager
T1003.004 LSA Secrets
T1005 Data from Local System
T1016.001 Internet Connection Discovery
T1021.007 Cloud Services
T1027.001 Binary Padding
T1027.002 Software Packing
T1027.006 HTML Smuggling
T1036.005 Match Legitimate Resource Name or Location
T1037 Boot or Logon Initialization Scripts
T1037.004 RC Scripts
T1047 Windows Management Instrumentation

(First 12 of 115 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Apt28 — Russia-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G0016 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.