Threat Intelligence / Actor / APT29
APT29
As of 2026-09-11, APT29 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 8 threats spanning apt, phishing, cloud. Also known as UNC2452, Cozy Bear, Midnight Blizzard, SVR. ATT&CK coverage spans 105 techniques across 16 tactics in 8 of 8 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1071 (Application Layer Protocol), T1528 (Steal Application Access Token).
Also known as: UNC2452, Cozy Bear, Midnight Blizzard, SVR, ATK7, Blue Kitsune, BlueBravo, Cloaked Ursa, CozyDuke, Dark Halo, G0016, Grizzly Steppe
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Defense Evasion — observed in 6 of 8 tracked threats
- T1071 Application Layer Protocol — Command And Control — observed in 5 of 8 tracked threats
- T1528 Steal Application Access Token — Credential Access — observed in 5 of 8 tracked threats
- T1566 Phishing — Initial Access — observed in 5 of 8 tracked threats
- T1114 Email Collection — Collection — observed in 4 of 8 tracked threats
- T1583 Acquire Infrastructure — Resource Development — observed in 4 of 8 tracked threats
- T1588 Obtain Capabilities — Resource Development — observed in 4 of 8 tracked threats
- T1005 Data from Local System — Collection — observed in 3 of 8 tracked threats
- T1036 Masquerading — Defense Evasion — observed in 3 of 8 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 8 tracked threats
- T1071.001 Web Protocols — Command And Control — observed in 3 of 8 tracked threats
- T1078 Valid Accounts — Initial Access — observed in 3 of 8 tracked threats
- T1087 Account Discovery — Discovery — observed in 3 of 8 tracked threats
- T1098 Account Manipulation — Persistence — observed in 3 of 8 tracked threats
- T1105 Ingress Tool Transfer — Command And Control — observed in 3 of 8 tracked threats
Tracked threats
- Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi (CaptiveCrunch), and Take Over WhatsApp Accounts Against Ukrainian/European Government and Drone-Supply-Chain Targets — HIGH
- Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US — HIGH
- Microsoft 365 Device Code Phishing Campaign Abusing the OAuth 2.0 Device Authorization Grant Flow (EvilTokens PhaaS) — HIGH
- ROADtools Misuse in Cloud Intrusions — Nation-State Abuse of the Open-Source Entra ID Offensive Toolkit (Unit 42) — HIGH
- Device Code Phishing Surge — 37x Increase Driven by EvilTokens and VENOM PhaaS Kits Targeting Microsoft 365 — HIGH
- Microsoft MSHTML Remote Code Execution Zero-Day (CVE-2026-21513) — CRITICAL
- Screensaver (.SCR) Files Used as Initial Access Vector — HIGH
- CVE-2026-21509: Russian Hackers Exploit Microsoft Office Vulnerability Against Ukraine — CRITICAL
Related CVEs
CVE-2026-21513, CVE-2026-21509
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →