Also known as: Dukes, Group 100, Cozy Duke, EuroAPT, Cozy Bear, CozyCar, Cozer, Office Monkeys / TEMP.Monkeys, Minidionis, SeaDuke, Hammer Toss, Fritillary, IRON HEMLOCK, The Dukes, YTTRIUM, Grizzly Steppe, G0016, ATK7, Cloaked Ursa, TA421, Blue Kitsune, ITG11, BlueBravo, Nobelium, UAC-0029, DarkHalo, StellarParticle, Solar Phoenix, Midnight Blizzard, ICECAP, ICE RELIC, IRON RITUAL, NobleBaron, Dark Halo, UNC2452, CozyDuke, SolarStorm, UNC3524, techniques, vaccine espionage, tracked as, CozyBear, ROOTSAW, VaporRage by Microsoft
**Targets:** This threat actor targets government ministries and agencies in Europe, the US, Central Asia, East Africa, and the Middle East, associated with DNC attacks **Toolset/Malware:** Hammertoss, OnionDuke, CosmicDuke, MiniDuke, CozyDuke, SeaDuke, SeaDaddy implant developed in Python and compiled with py2exe, AdobeARM, ATI-Agent, MiniDionis, Grizzly Steppe, Vernaldrop, Tadpole, Spikerush, POSHSPY, PolyglotDuke, RegDuke, FatDuke **Modus Operandi:** Phishing emails **Operations:** Operation Ghost **Notes:** Active campaign post 2016 US presidential election
Phishing emails
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT29, also known as Dukes, Group 100, and Cozy Bear, is a nation-state threat actor primarily involved in espionage activities targeting government ministries and agencies across Europe, the US, Central Asia, East Africa, and the Middle East. Known for their sophisticated phishing campaigns, APT29 has been linked to operations such as Operation Ghost, which gained attention post the 2016 US presidential election.
Goals & Targeting
APT29's strategic objectives revolve around情报 and political gathering through cyber espionage. They specifically target government sectors due to the sensitivity of the information held, with a focus on diplomatic offices and ministries in Europe, Central Asia, and the Middle East. Their targeting reflects a desire to influence geopolitical dynamics by compromising sensitive data.
Enhanced Description
APT29 is a high-sophistication nation-state actor known for targeting government entities to gather political and economic intelligence. They primarily use phishing emails as their attack vector, leveraging malware like CozyDuke, MiniDuke, and others. Their operations often involve credential theft and persistence mechanisms using tools such as PowerDuke and Cobalt Strike. APT29's campaigns are characterized by their patient and targeted approach, aiming to infiltrate sensitive systems for long-term espionage activities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT29's operations include campaigns like Operation Ghost, which targeted US government and political organizations post the 2016 election. Their modus operandi typically involves phishing emails with malware payloads to gain unauthorized access to systems, followed by lateral movement and data exfiltration. APT29 is known for maintaining long-term persistence within networks to gather extensive intelligence over time.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in APT29's activities is high due to extensive evidence from tracked campaigns and technical details. However, gaps exist in fully understanding their exact methods and long-term objectives.
Operation Ghost
No observed data linked yet.
97
Techniques
67
Tools
1
Campaigns
40
IOCs
0
Observed Data
13
Tactics