Threat actor · all actors
APT29G0016 state
🇷🇺 RU · SVR
aka APT29, IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard, Group 100, Minidionis, SeaDuke, Grizzly Steppe, G0016, ATK7, Cloaked Ursa, TA421, ITG11, BlueBravo, UAC-0029, ICECAP, ICE RELIC, DarkHalo, StellarParticle, Solar Phoenix
Last updated: 2026-08-22
About this actor
[APT29](https://attack.mitre.org/groups/G0016) is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).(Citation: White House Imposing Costs RU Gov April 2021)(Citation: UK Gov Malign RIS Activity April 2021) They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. [APT29](https://attack.mitre.org/groups/G0016) reportedly compromised the Democratic National Committee starting in the summer of 2015.(Citation: F-Secure The Dukes)(Citation: GRIZZLY STEPPE JAR)(Citation: Crowdstrike DNC June 2016)(Citation: UK Gov UK Exposes Russia SolarWinds April 2021) In April 2021, the US and UK governments attributed the [SolarWinds Compromise](https://attack.mitre.org/campaigns/C0024) to the SVR; public statements included citations to [APT29](https://attack.mitre.org/groups/G0016), Cozy Bear, and The Dukes.(Citation: NSA Joint Advisory SVR SolarWinds April 2021)(Citation: UK NSCS Russia SolarWinds April 2021) Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.(Citation: FireEye SUNBURST Backdoor December 2020)(Citation: MSTIC NOBELIUM Mar 2021)(Citation: CrowdStrike SUNSPOT Implant January 2021)(Citation: Volexity SolarWinds)(Citation: Cybersecurity Advisory SVR TTP May 2021)(Citation: Unit 42 SolarStorm December 2020)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Mandiant / genericAPT numbering
MandiantUNC uncategorised cluster
Secureworkscolour-metal names
CERT-UAUAC cluster id
ProofpointTA threat-actor id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 96 ATT&CK techniques on file.
- Named victims
- 2 extracted from reporting.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
- 2022 — 1 KEV added
- 2021 — 1 CVE published
- 2010 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2010-0232 KEV | 8.5 | 7.8 | 0.7656 | 2010-01-21 | see CVE |
CVE-2020-8554 | 6.5 | 6.3 | 0.3120 | 2021-01-21 | see CVE |
CVE-2026-20929 | 5.9 | 7.5 | 0.0116 | 2026-01-13 | see CVE |
T1003OS Credential Dumping ↗T1003.002Security Account Manager ↗T1003.004LSA Secrets ↗T1005Data from Local System ↗T1016System Network Configuration Discovery ↗T1016.001Internet Connection Discovery ↗T1021Remote Services ↗T1021.007Cloud Services ↗T1027Obfuscated Files or Information ↗T1027.001Binary Padding ↗T1027.002Software Packing ↗T1027.006HTML Smuggling ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1037Boot or Logon Initialization Scripts ↗T1037.004RC Scripts ↗T1047Windows Management Instrumentation ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.006Python ↗T1059.009Cloud API ↗T1068Exploitation for Privilege Escalation ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1070.006Timestomp ↗T1078Valid Accounts ↗T1078.003Local Accounts ↗T1078.004Cloud Accounts ↗T1087Account Discovery ↗T1087.004Cloud Account ↗T1090Proxy ↗T1090.002External Proxy ↗T1090.003Multi-hop Proxy ↗T1090.004Domain Fronting ↗T1098Account Manipulation ↗T1098.002Additional Email Delegate Permissions ↗T1098.005Device Registration ↗T1105Ingress Tool Transfer ↗T1110Brute Force ↗T1110.001Password Guessing ↗T1110.003Password Spraying ↗T1114Email Collection ↗T1114.002Remote Email Collection ↗T1133External Remote Services ↗T1136Create Account ↗T1136.003Cloud Account ↗T1190Exploit Public-Facing Application ↗T1199Trusted Relationship ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1218System Binary Proxy Execution ↗T1218.005Mshta ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1528Steal Application Access Token ↗T1546Event Triggered Execution ↗T1546.003Windows Management Instrumentation Event Subscription ↗T1546.008Accessibility Features ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1548Abuse Elevation Control Mechanism ↗T1548.002Bypass User Account Control ↗T1550Use Alternate Authentication Material ↗T1550.003Pass the Ticket ↗T1553Subvert Trust Controls ↗T1553.005Mark-of-the-Web Bypass ↗T1556Modify Authentication Process ↗T1556.007Hybrid Identity ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1566.003Spearphishing via Service ↗T1568Dynamic Resolution ↗T1573Encrypted Channel ↗T1583Acquire Infrastructure ↗T1583.006Web Services ↗T1586Compromise Accounts ↗T1586.002Email Accounts ↗T1586.003Cloud Accounts ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1587.003Digital Certificates ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1595Active Scanning ↗T1595.002Vulnerability Scanning ↗T1621Multi-Factor Authentication Request Generation ↗T1649Steal or Forge Authentication Certificates ↗T1651Cloud Administration Command ↗T1665Hide Infrastructure ↗T1685Disable or Modify Tools ↗T1685.002Disable or Modify Cloud Log ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 63 / 96 | 66% |
CM-6 | 61 / 96 | 64% |
AC-3 | 54 / 96 | 56% |
AC-6 | 51 / 96 | 53% |
AC-2 | 49 / 96 | 51% |
CM-2 | 47 / 96 | 49% |
IA-2 | 41 / 96 | 43% |
CA-7 | 38 / 96 | 40% |
CM-7 | 38 / 96 | 40% |
AC-5 | 36 / 96 | 38% |
SI-3 | 35 / 96 | 36% |
SI-7 | 33 / 96 | 34% |
CM-5 | 32 / 96 | 33% |
AC-4 | 26 / 96 | 27% |
SC-7 | 24 / 96 | 25% |
Co-occurring actors
- SolarWinds Compromise 2 shared CVEs
- Ajax Security Team 1 shared CVEs
- APT38 1 shared CVEs
- Sandworm Team 1 shared CVEs
- Tonto Team 1 shared CVEs
- GOLD SOUTHFIELD 1 shared CVEs
- Scattered Spider 1 shared CVEs
- OilRig 1 shared CVEs
- Indrik Spider 1 shared CVEs
- Mustang Panda 1 shared CVEs
Similar actors
Similar TTPs
- APT28 0.31
- Magic Hound 0.29
- Dragonfly 0.28
- OilRig 0.27
- TA2541 0.27
Overlapping CVEs
- SolarWinds Compromise 0.67
- C0027 0.33
- APT12 0.33
- APT28 0.33
- FIN7 0.33
Active in same years
- Threat Group-3390 3.00
- Sandworm Team 3.00
- SolarWinds Compromise 2.00
- SharePoint ToolShell Exploitation 2.00
- Naikon 2.00
Same nation-state
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00