G0016 · 121 ATT&CK techniques · 9 correlated reports

APT29

Aliases: IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015. In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.

Open interactive actor investigation

ATT&CK techniques

T1621
Multi-Factor Authentication Request Generation
T1003.002
Security Account Manager
T1588.002
Tool
T1090.004
Domain Fronting
T1528
Steal Application Access Token
T1568
Dynamic Resolution
T1068
Exploitation for Privilege Escalation
T1546.003
Windows Management Instrumentation Event Subscription
T1547.001
Registry Run Keys / Startup Folder
T1136.003
Cloud Account
T1098.005
Device Registration
T1587.003
Digital Certificates
T1005
Data from Local System
T1105
Ingress Tool Transfer
T1651
Cloud Administration Command
T1566.001
Spearphishing Attachment
T1078.004
Cloud Accounts
T1053.005
Scheduled Task
T1016.001
Internet Connection Discovery
T1587.001
Malware
T1583.006
Web Services
T1090.003
Multi-hop Proxy
T1037
Boot or Logon Initialization Scripts
T1027.006
HTML Smuggling
T1070.004
File Deletion
T1203
Exploitation for Client Execution
T1550.003
Pass the Ticket
T1204.001
Malicious Link
T1036.005
Match Legitimate Name or Location
T1110.003
Password Spraying
T1114.002
Remote Email Collection
T1027.001
Binary Padding
T1556.007
Hybrid Identity
T1059.001
PowerShell
T1133
External Remote Services
T1037.004
RC Scripts
T1021.007
Cloud Services
T1595.002
Vulnerability Scanning
T1566.002
Spearphishing Link
T1070.006
Timestomp
T1586.003
Cloud Accounts
T1090.002
External Proxy
T1573
Encrypted Channel
T1047
Windows Management Instrumentation
T1110.001
Password Guessing
T1199
Trusted Relationship
T1566.003
Spearphishing via Service
T1078
Valid Accounts
T1505.003
Web Shell
T1059.006
Python
T1665
Hide Infrastructure
T1218.005
Mshta
T1003.004
LSA Secrets
T1190
Exploit Public-Facing Application
T1553.005
Mark-of-the-Web Bypass
T1649
Steal or Forge Authentication Certificates
T1087.004
Cloud Account
T1098.002
Additional Email Delegate Permissions
T1078.003
Local Accounts
T1546.008
Accessibility Features
T1059.009
Cloud API
T1586.002
Email Accounts
T1562.008
Disable or Modify Cloud Logs
T1204.002
Malicious File
T1548.002
Bypass User Account Control
T1027.002
Software Packing
T1562.001
Disable or Modify Tools
T1036.004
Masquerade Task or Service
T1059.003
Windows Command Shell
T1140
Deobfuscate/Decode Files or Information
T1550.004
Web Session Cookie
T1003.006
DCSync
T1560.001
Archive via Utility
T1069.002
Domain Groups
T1059.005
Visual Basic
T1027
Obfuscated Files or Information
T1213
Data from Information Repositories
T1555
Credentials from Password Stores
T1057
Process Discovery
T1087
Account Discovery
T1583.001
Domains
T1036
Masquerading
T1083
File and Directory Discovery
T1070
Indicator Removal
T1195.002
Compromise Software Supply Chain
T1484.002
Trust Modification
T1098.001
Additional Cloud Credentials
T1078.002
Domain Accounts
T1069
Permission Groups Discovery
T1550
Use Alternate Authentication Material
T1021.001
Remote Desktop Protocol
T1584.001
Domains
T1550.001
Application Access Token
T1213.003
Code Repositories
T1021.006
Windows Remote Management
T1606.001
Web Cookies
T1082
System Information Discovery
T1482
Domain Trust Discovery
T1095
Non-Application Layer Protocol
T1074.002
Remote Data Staging
T1090.001
Internal Proxy
T1001.002
Steganography
T1589.001
Credentials
T1102.002
Bidirectional Communication
T1555.003
Credentials from Web Browsers
T1606.002
SAML Tokens
T1553.002
Code Signing
T1562.004
Disable or Modify System Firewall
T1070.008
Clear Mailbox Data
T1552.004
Private Keys
T1218.011
Rundll32
T1021.002
SMB/Windows Admin Shares
T1071.001
Web Protocols
T1562.002
Disable Windows Event Logging
T1098.003
Additional Cloud Roles
T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
T1539
Steal Web Session Cookie
T1558.003
Kerberoasting
T1018
Remote System Discovery
T1087.002
Domain Account
T1547.009
Shortcut Modification

Correlated CTI and IR reports

Continue the investigation