APT29

G0016

Threat group.View on attack.mitre.org

About this group

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015.

In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.

Techniques used66

Procedure examples66

TechniqueProcedure example
T1003.002
Security Account Manager

APT29 has used the `reg save` command to save registry hives.

T1003.004
LSA Secrets

APT29 has used the `reg save` command to extract LSA secrets offline.

T1005
Data from Local System

APT29 has stolen data from compromised hosts.

T1016.001
Internet Connection Discovery

APT29 has ensured web servers in a victim environment are Internet accessible before copying tools or malware to it.

T1021.007
Cloud Services

APT29 has leveraged compromised high-privileged on-premises accounts synced to Office 365 to move laterally into a cloud environment, including through the use of Azure AD PowerShell.

T1027.001
Binary Padding

APT29 used large size files to avoid detection by security solutions with hardcoded size limits.

T1027.002
Software Packing

APT29 used UPX to pack files.

T1027.006
HTML Smuggling

APT29 has embedded an ISO file within an HTML attachment that contained JavaScript code to initiate malware execution.

T1036.005
Match Legitimate Resource Name or Location

APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal.

T1037
Boot or Logon Initialization Scripts

APT29 has hijacked legitimate application-specific startup scripts to enable malware to execute on system startup.

T1037.004
RC Scripts

APT29 has installed a run command on a compromised system to enable malware execution on system startup.

T1047
Windows Management Instrumentation

APT29 used WMI to steal credentials and execute backdoors at a future time.

T1053.005
Scheduled Task

APT29 has used named and hijacked scheduled tasks to establish persistence.

T1059.001
PowerShell

APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke.

T1059.006
Python

APT29 has developed malware variants written in Python.

View all 66 procedure examples

Software49

Show 25 more

Campaigns2

References14

  1. CrowdStrike SUNSPOT Implant January 2021 Open source
    CrowdStrike Intelligence Team. (2021, January 11). SUNSPOT: An Implant in the Build Process. Retrieved January 11, 2021.
  2. Crowdstrike DNC June 2016 Open source
    Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.
  3. Cybersecurity Advisory SVR TTP May 2021 Open source
    NCSC, CISA, FBI, NSA. (2021, May 7). Further TTPs associated with SVR cyber actors. Retrieved July 29, 2021.
  4. F-Secure The Dukes Open source
    F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.
  5. FireEye SUNBURST Backdoor December 2020 Open source
    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.
  6. GRIZZLY STEPPE JAR Open source
    Department of Homeland Security and Federal Bureau of Investigation. (2016, December 29). GRIZZLY STEPPE – Russian Malicious Cyber Activity. Retrieved January 11, 2017.
  7. MSTIC NOBELIUM Mar 2021 Open source
    Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.
  8. NSA Joint Advisory SVR SolarWinds April 2021 Open source
    NSA, FBI, DHS. (2021, April 15). Russian SVR Targets U.S. and Allied Networks. Retrieved April 16, 2021.
  9. UK Gov Malign RIS Activity April 2021 Open source
    UK Gov. (2021, April 15). UK and US expose global campaign of malign activity by Russian intelligence services . Retrieved April 16, 2021.
  10. UK Gov UK Exposes Russia SolarWinds April 2021 Open source
    UK Gov. (2021, April 15). UK exposes Russian involvement in SolarWinds cyber compromise . Retrieved April 16, 2021.
  11. UK NSCS Russia SolarWinds April 2021 Open source
    UK NCSC. (2021, April 15). UK and US call out Russia for SolarWinds compromise. Retrieved April 16, 2021.
  12. Unit 42 SolarStorm December 2020 Open source
    Unit 42. (2020, December 23). SolarStorm Supply Chain Attack Timeline. Retrieved March 24, 2023.
  13. Volexity SolarWinds Open source
    Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020.
  14. White House Imposing Costs RU Gov April 2021 Open source
    White House. (2021, April 15). Imposing Costs for Harmful Foreign Activities by the Russian Government. Retrieved April 16, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.