Threat group.View on attack.mitre.org
APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015.
In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.
| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
APT29 has used the `reg save` command to save registry hives. |
| T1003.004 LSA Secrets |
APT29 has used the `reg save` command to extract LSA secrets offline. |
| T1005 Data from Local System |
APT29 has stolen data from compromised hosts. |
| T1016.001 Internet Connection Discovery |
APT29 has ensured web servers in a victim environment are Internet accessible before copying tools or malware to it. |
| T1021.007 Cloud Services |
APT29 has leveraged compromised high-privileged on-premises accounts synced to Office 365 to move laterally into a cloud environment, including through the use of Azure AD PowerShell. |
| T1027.001 Binary Padding |
APT29 used large size files to avoid detection by security solutions with hardcoded size limits. |
| T1027.002 Software Packing |
APT29 used UPX to pack files. |
| T1027.006 HTML Smuggling |
APT29 has embedded an ISO file within an HTML attachment that contained JavaScript code to initiate malware execution. |
| T1036.005 Match Legitimate Resource Name or Location |
APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal. |
| T1037 Boot or Logon Initialization Scripts |
APT29 has hijacked legitimate application-specific startup scripts to enable malware to execute on system startup. |
| T1037.004 RC Scripts |
APT29 has installed a run command on a compromised system to enable malware execution on system startup. |
| T1047 Windows Management Instrumentation |
APT29 used WMI to steal credentials and execute backdoors at a future time. |
| T1053.005 Scheduled Task |
APT29 has used named and hijacked scheduled tasks to establish persistence. |
| T1059.001 PowerShell |
APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. |
| T1059.006 Python |
APT29 has developed malware variants written in Python. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.