# Midnight Blizzard

> As of 2026-09-29, Midnight Blizzard is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 7 threats spanning apt, phishing, zero day. Also known as UNC2452, Cozy Bear, NOBELIUM. ATT&CK coverage spans 78 techniques across 14 tactics in 7 of 7 tracked threats. Most-observed techniques: T1528 (Steal Application Access Token), T1027 (Obfuscated Files or Information), T1071.001 (Web Protocols).

- **Nation:** Russia
- **Tracked threats:** 7
- **Categories:** APT, PHISHING, ZERO_DAY
- **Also known as:** UNC2452, Cozy Bear, NOBELIUM
- **As of:** 2026-09-29

## ATT&CK techniques observed

78 techniques observed across 7 of 7 tracked threats. Tactics: Credential Access (11), Stealth (formerly Defense Evasion) (11), Execution (9), Persistence (8), Collection (7), Command and Control (7).

- [T1528](https://attack.mitre.org/techniques/T1528/) Steal Application Access Token — Credential Access — observed in 6 of 7 tracked threats
- [T1027](https://attack.mitre.org/techniques/T1027/) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 7 tracked threats
- [T1071.001](https://attack.mitre.org/techniques/T1071/001/) Web Protocols — Command and Control — observed in 4 of 7 tracked threats
- [T1078](https://attack.mitre.org/techniques/T1078/) Valid Accounts — Initial Access — observed in 4 of 7 tracked threats
- [T1543.003](https://attack.mitre.org/techniques/T1543/003/) Create or Modify System Process: Windows Service — Persistence — observed in 4 of 7 tracked threats
- [T1548.002](https://attack.mitre.org/techniques/T1548/002/) Bypass User Account Control — Privilege Escalation — observed in 4 of 7 tracked threats
- [T1685](https://attack.mitre.org/techniques/T1685/) Disable or Modify Tools — Defense Impairment — observed in 4 of 7 tracked threats
- [T1053.005](https://attack.mitre.org/techniques/T1053/005/) Scheduled Task — Persistence — observed in 3 of 7 tracked threats
- [T1056.001](https://attack.mitre.org/techniques/T1056/001/) Keylogging — Credential Access — observed in 3 of 7 tracked threats
- [T1059.001](https://attack.mitre.org/techniques/T1059/001/) PowerShell — Execution — observed in 3 of 7 tracked threats
- [T1071](https://attack.mitre.org/techniques/T1071/) Application Layer Protocol — Command and Control — observed in 3 of 7 tracked threats
- [T1113](https://attack.mitre.org/techniques/T1113/) Screen Capture — Collection — observed in 3 of 7 tracked threats
- [T1114](https://attack.mitre.org/techniques/T1114/) Email Collection — Collection — observed in 3 of 7 tracked threats
- [T1123](https://attack.mitre.org/techniques/T1123/) Audio Capture — Collection — observed in 3 of 7 tracked threats
- [T1204](https://attack.mitre.org/techniques/T1204/) User Execution — Execution — observed in 3 of 7 tracked threats

## Tracked threats

- [Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi (CaptiveCrunch), and Take Over WhatsApp Accounts Against Ukrainian/European Government and Drone-Supply-Chain Targets](https://intel.threadlinqs.com/threat/TL-2026-2446) — HIGH
- [Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US](https://intel.threadlinqs.com/threat/TL-2026-2091) — HIGH
- [CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deploy CornFlake RAT and ChocoShell Info-Stealer Against Corporate Travelers](https://intel.threadlinqs.com/threat/TL-2026-1853) — CRITICAL
- [CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaign](https://intel.threadlinqs.com/threat/TL-2026-2765) — HIGH
- [Microsoft 365 Device Code Phishing Campaign Abusing the OAuth 2.0 Device Authorization Grant Flow (EvilTokens PhaaS)](https://intel.threadlinqs.com/threat/TL-2026-0824) — HIGH
- [Device Code Phishing Surge — 37x Increase Driven by EvilTokens and VENOM PhaaS Kits Targeting Microsoft 365](https://intel.threadlinqs.com/threat/TL-2026-0323) — HIGH
- [Microsoft MSHTML Remote Code Execution Zero-Day (CVE-2026-21513)](https://intel.threadlinqs.com/threat/TL-2026-0175) — CRITICAL

## Related CVEs

1 CVE referenced by tracked Midnight Blizzard activity.

- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Midnight%20Blizzard
