Threat Intelligence / Actor / Midnight Blizzard
Midnight Blizzard
As of 2026-09-29, Midnight Blizzard is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 7 threats spanning apt, phishing, zero day. Also known as UNC2452, Cozy Bear, NOBELIUM. ATT&CK coverage spans 78 techniques across 14 tactics in 7 of 7 tracked threats. Most-observed techniques: T1528 (Steal Application Access Token), T1027 (Obfuscated Files or Information), T1071.001 (Web Protocols).
Also known as: UNC2452, Cozy Bear, NOBELIUM
ATT&CK techniques observed
- T1528 Steal Application Access Token — Credential Access — observed in 6 of 7 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 7 tracked threats
- T1071.001 Web Protocols — Command and Control — observed in 4 of 7 tracked threats
- T1078 Valid Accounts — Initial Access — observed in 4 of 7 tracked threats
- T1543.003 Create or Modify System Process: Windows Service — Persistence — observed in 4 of 7 tracked threats
- T1548.002 Bypass User Account Control — Privilege Escalation — observed in 4 of 7 tracked threats
- T1685 Disable or Modify Tools — Defense Impairment — observed in 4 of 7 tracked threats
- T1053.005 Scheduled Task — Persistence — observed in 3 of 7 tracked threats
- T1056.001 Keylogging — Credential Access — observed in 3 of 7 tracked threats
- T1059.001 PowerShell — Execution — observed in 3 of 7 tracked threats
- T1071 Application Layer Protocol — Command and Control — observed in 3 of 7 tracked threats
- T1113 Screen Capture — Collection — observed in 3 of 7 tracked threats
- T1114 Email Collection — Collection — observed in 3 of 7 tracked threats
- T1123 Audio Capture — Collection — observed in 3 of 7 tracked threats
- T1204 User Execution — Execution — observed in 3 of 7 tracked threats
Tracked threats
- Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi (CaptiveCrunch), and Take Over WhatsApp Accounts Against Ukrainian/European Government and Drone-Supply-Chain Targets — HIGH
- Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US — HIGH
- CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deploy CornFlake RAT and ChocoShell Info-Stealer Against Corporate Travelers — CRITICAL
- CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaign — HIGH
- Microsoft 365 Device Code Phishing Campaign Abusing the OAuth 2.0 Device Authorization Grant Flow (EvilTokens PhaaS) — HIGH
- Device Code Phishing Surge — 37x Increase Driven by EvilTokens and VENOM PhaaS Kits Targeting Microsoft 365 — HIGH
- Microsoft MSHTML Remote Code Execution Zero-Day (CVE-2026-21513) — CRITICAL
Related CVEs
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →