Home
Glossary
APT29 aka Nobelium, Cozy Bear
Table of contents
5 min
H2 title on one or more lines.
Share
Updated on
June 22, 2026

APT29 (as known as Cozy Bear or Midnight Blizzard) threat actor

APT29 is a Russian state-sponsored cyber espionage group attributed by the US, UK, and other governments to Russia's Foreign Intelligence Service (SVR). Active since at least 2008, it's one of the most capable and persistent nation-state actors tracked by the security community, defined by operational stealth, long dwell times, and a focus on intelligence collection rather than disruption or destruction. APT29 is also widely known as Cozy Bear, Midnight Blizzard (Microsoft's current designation), Nobelium, and The Dukes; MITRE ATT&CK tracks it as G0016. It's best known for the 2020 SolarWinds supply chain compromise and, more recently, for breaching Microsoft's corporate systems. Unlike noisier actors, APT29 prioritizes operational security and hard-to-detect access, and it has steadily shifted from malware-heavy intrusions toward cloud- and identity-focused tradecraft. This page covers the group's attribution and aliases, its place in the Russian threat ecosystem, its notable campaigns, how it operates today, and how organizations can defend against it.

Key takeaways

  • APT29 is attributed to Russia's SVR. US, UK, and allied governments assess the group is almost certainly part of Russia's Foreign Intelligence Service, conducting espionage aligned with Kremlin priorities.
  • It goes by many names. Cozy Bear, Midnight Blizzard, Nobelium, The Dukes, UNC2452, and Dark Halo all refer to the same actor, tracked by MITRE as G0016.
  • Espionage and stealth define it. APT29 favors long-dwell, low-noise intrusions to steal sensitive government, diplomatic, and research information, distinguishing it from disruptive or destructive actors.
  • SolarWinds was its landmark operation. The 2020 supply chain compromise via SUNBURST reached roughly 18,000 organizations and reset industry expectations about supply chain risk.
  • It has moved to the cloud. APT29 increasingly targets identity systems, OAuth tokens, and cloud platforms, using living-off-the-land techniques to blend in and avoid deploying detectable malware.

Attribution and aliases

APT29 has been attributed to the SVR by multiple governments and cybersecurity vendors, backed by strong forensic and analytic evidence: consistent operational infrastructure, distinctive malware development patterns, targeting that matches SVR intelligence priorities, activity aligned with Moscow working hours, and Russian-language artifacts. Formal attribution statements accompanied the SolarWinds disclosures in 2021 from the US and UK, and UK, US, and Dutch reporting has repeatedly reinforced the SVR link.

Because so many vendors have tracked the group independently, it carries an unusually large set of names. The most common are Cozy Bear, Midnight Blizzard (Microsoft's current naming), Nobelium, and The Dukes. Others include UNC2452, Dark Halo, CozyDuke, YTTRIUM, Cloaked Ursa, IRON RITUAL, IRON HEMLOCK, NobleBaron, StellarParticle, and BlueBravo. They all point to the same actor, which is why cross-referencing vendor reporting matters when researching it.

APT29 in the Russian threat ecosystem

APT29 is one of three commonly cited Russian state-linked cyber actors, and distinguishing them is useful because their doctrine and behavior differ.

APT29 (SVR) is the espionage specialist: patient, stealthy, and focused on quiet intelligence collection over months or years. APT28, known as Fancy Bear, is attributed to the military intelligence agency GRU and is associated with more aggressive and disruptive operations. Turla is linked to the FSB and is another long-running espionage actor. Where a GRU-linked group might prioritize speed and impact, APT29's SVR tradecraft favors remaining undetected indefinitely to keep collecting. That distinction matters for defense: APT29 doesn't want to be found, which makes behavioral detection and threat intelligence more effective than reactive incident response alone.

Notable campaigns

APT29's operational history spans more than a decade and tracks closely with Russian strategic interests.

The Dukes era (2008–2014)

Early campaigns used a family of custom tools often referred to as the Dukes, including MiniDuke, CosmicDuke, SeaDuke, and CozyDuke, targeting European ministries, NATO, and US think tanks. The targeting discipline and espionage focus were already characteristic. Kaspersky published early public reporting on the actor, and a 2014 operation by Dutch intelligence gave rare first-hand visibility into the group.

US government and DNC (2014–2016)

APT29 was linked to intrusions at the US State Department and White House email systems around 2014–2015, and to the 2015–2016 compromise of the Democratic National Committee (DNC), activity later folded into US government reporting under the name GRIZZLY STEPPE. This period cemented the group's reputation for high-value political intelligence targets.

COVID-19 vaccine targeting (2020)

In 2020, UK, US, and Canadian agencies warned that APT29 was targeting organizations involved in COVID-19 vaccine development using custom malware known as WellMess and WellMail. A clear example of espionage aligned with a national strategic priority: whoever controls a vaccine also controls a negotiating asset.

SolarWinds / SUNBURST (2020)

APT29's most consequential operation compromised the software build process of SolarWinds' Orion IT management product and embedded the SUNBURST backdoor into signed, trusted updates. That supply chain compromise distributed malware to roughly 18,000 organizations, and the actors selectively activated follow-on tooling, including TEARDROP, against high-value targets including multiple US federal agencies and major technology firms. Reporting indicated the group maintained access for months before detection. SolarWinds reset how the industry thinks about supply chain and trust-relationship risk.

Microsoft and cloud-era breaches (2023–2024)

More recently, APT29 breached Microsoft's corporate email systems in an intrusion disclosed in early 2024, using password-spray attacks and OAuth abuse to reach executive and security-team mailboxes. A comparable intrusion at Hewlett Packard Enterprise was linked to the same actor. These incidents illustrate the group's decisive shift toward identity- and cloud-focused operations: no custom malware, just stolen tokens and abused legitimate services.

How APT29 operates

APT29's tradecraft has evolved from custom malware toward abusing legitimate services and identity, but a few themes are constant: stealth, redundancy of access, and blending into normal activity. Its techniques map cleanly onto the MITRE ATT&CK framework.

Stage Representative techniques
Initial access Targeted spearphishing, password spraying against cloud accounts, exploitation of internet-facing services, and supply chain compromise (as with SolarWinds).
Persistence & privilege OAuth application and refresh-token abuse, forged SAML tokens (Golden SAML), ADFS abuse, and custom backdoors on-premises.
Defense evasion Living off the land with PowerShell and WMI, redundant implants, and command-and-control blended into trusted services such as Microsoft 365, Dropbox, and Google Drive.
Collection & exfiltration Access to email and document stores, selective and low-volume exfiltration timed to avoid triggering alerts.

On the malware side, the group has used families including SUNBURST and TEARDROP (SolarWinds), WellMess and WellMail (vaccine targeting), GoldMax, HAMMERTOSS, and ADFS-focused implants such as FOGGYWEB and MAGICWEB. Increasingly, though, APT29 favors credential and token abuse over malware. Much of the activity looks like legitimate authenticated access, which is exactly what makes it hard to detect and why identity and behavioral monitoring matter more than signature-based tools for this actor.

Who APT29 targets

APT29's targeting is consistent with SVR intelligence collection rather than financial gain or disruption. Primary targets include Western governments, diplomatic missions and foreign ministries, think tanks and policy research institutes, NGOs, defense and aerospace sectors, and the IT service providers and cloud tenants that support them. Attacks on supply chains and service providers are especially valuable because they offer access to many downstream victims at once, a pattern SolarWinds made vivid.

How to defend against APT29

Because the group now leans on identity and legitimate services rather than obvious malware, defense centers on identity security, cloud posture, and behavioral detection:

  1. Harden identity and authentication. Enforce phishing-resistant multi-factor authentication (MFA), minimize and monitor privileged accounts, and defend against password spraying, a recurring APT29 initial-access method.
  2. Secure OAuth apps and federation. Audit and restrict OAuth application consent, monitor service principals and app registrations, and protect SAML signing certificates and federation (ADFS) trust, which the group has repeatedly abused.
  3. Watch cloud and email for anomalous access. Since much activity looks like valid authenticated sessions, behavioral monitoring of Microsoft 365 and cloud tenants (unusual token use, mailbox access, or admin actions) is more effective than signature-based tools alone.
  4. Manage supply chain and third-party trust. Vet software and service providers, monitor for anomalous behavior in trusted software, and limit the blast radius of any single trusted integration.
  5. Hunt for living-off-the-land activity. Monitor PowerShell, WMI, and other native tooling for suspicious use, and correlate signals across endpoint, identity, and cloud to surface stealthy, low-volume intrusions.

Expert insight: Detecting an actor that avoids malware

The hardest thing about defending against APT29 is that its best tradecraft leaves little for traditional tools to catch. When an intrusion relies on a stolen OAuth token, a forged SAML assertion, or a valid credential obtained by password spraying, there's often no malicious file to detonate and no obvious exploit to block. The meaningful signals are behavioral: an authenticated session from an unexpected context, a new service principal with broad permissions, or a quiet pattern of mailbox access that never spikes.

This is where a CTI-led approach is relevant. Sekoia is a European cybersecurity vendor whose in-house Threat Detection & Research (TDR) team tracks nation-state actors such as APT29, and that intelligence feeds the platform so that known tradecraft, infrastructure, and technique patterns are recognized in context. Rather than waiting for a malware signature, Sekoia's AI SOC platform correlates telemetry across endpoint, identity, and cloud, and maps detections to MITRE ATT&CK, so the identity and cloud abuse APT29 favors surfaces as an alert rather than passing as normal authenticated activity. Native threat intelligence helps prioritize the sectors and techniques a given actor is most likely to use, and as a European vendor with a data-sovereignty posture, Sekoia is well placed to protect the government and diplomatic organizations this group most consistently targets.

Against an actor this disciplined, assume prevention will sometimes fail and invest in detection that spans identity, cloud, and endpoint together. Cross-surface behavioral visibility is the category of defense APT29's tradecraft was designed to evade, which is precisely why it's the right place to build.