Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Dukes, Group 100, Cozy Duke, EuroAPT, Cozy Bear, CozyCar, Cozer, Office Monkeys / TEMP.Monkeys, Minidionis, SeaDuke, Hammer Toss, Fritillary, IRON HEMLOCK, The Dukes, YTTRIUM, Grizzly Steppe, G0016, ATK7, Cloaked Ursa, TA421, Blue Kitsune, ITG11, BlueBravo, Nobelium, UAC-0029, DarkHalo, StellarParticle, Solar Phoenix, Midnight Blizzard, ICECAP, ICE RELIC, IRON RITUAL, NobleBaron, Dark Halo, UNC2452, CozyDuke, SolarStorm, UNC3524, techniques, vaccine espionage, tracked as, CozyBear, ROOTSAW, VaporRage by Microsoft

Description

**Targets:** This threat actor targets government ministries and agencies in Europe, the US, Central Asia, East Africa, and the Middle East, associated with DNC attacks **Toolset/Malware:** Hammertoss, OnionDuke, CosmicDuke, MiniDuke, CozyDuke, SeaDuke, SeaDaddy implant developed in Python and compiled with py2exe, AdobeARM, ATI-Agent, MiniDionis, Grizzly Steppe, Vernaldrop, Tadpole, Spikerush, POSHSPY, PolyglotDuke, RegDuke, FatDuke **Modus Operandi:** Phishing emails **Operations:** Operation Ghost **Notes:** Active campaign post 2016 US presidential election

TTP Summary

Phishing emails

Goals & Targeting

Targeted Sectors

Government
Think tank
Defense
Non profit
Energy
Healthcare
Telecommunications
Media
Pharmaceutical
Education
Aviation
Maritime
Aerospace
Financial services
Transportation
Utilities

Targeted Countries / Regions

middle_east
europe
central_asia
RU
US
GB
UA
NL
CA
KR
DE

AI Analysis

· 1 week ago

Executive Summary

APT29, also known as Dukes, Group 100, and Cozy Bear, is a nation-state threat actor primarily involved in espionage activities targeting government ministries and agencies across Europe, the US, Central Asia, East Africa, and the Middle East. Known for their sophisticated phishing campaigns, APT29 has been linked to operations such as Operation Ghost, which gained attention post the 2016 US presidential election.

Goals & Targeting

APT29's strategic objectives revolve around情报 and political gathering through cyber espionage. They specifically target government sectors due to the sensitivity of the information held, with a focus on diplomatic offices and ministries in Europe, Central Asia, and the Middle East. Their targeting reflects a desire to influence geopolitical dynamics by compromising sensitive data.

Enhanced Description

APT29 is a high-sophistication nation-state actor known for targeting government entities to gather political and economic intelligence. They primarily use phishing emails as their attack vector, leveraging malware like CozyDuke, MiniDuke, and others. Their operations often involve credential theft and persistence mechanisms using tools such as PowerDuke and Cobalt Strike. APT29's campaigns are characterized by their patient and targeted approach, aiming to infiltrate sensitive systems for long-term espionage activities.

Key Capabilities

  • CozyDuke
  • MiniDuke
  • SeaDuke
  • Hammertoss
  • CosmicDuke
  • OnionDuke
  • PowerDuke
  • Cobalt Strike

MITRE ATT&CK Tactics

Credential Access
Initial Access
Execution
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1053.005
T1037
T1566.003
T1110.001
T1394
T1016.001
T1003.002
T1036.005

Software / Tooling

PowerDuke
OnionDuke
Hammertoss
CosmicDuke
ReGeorg
Cobalt Strike

Campaigns & Victims

APT29's operations include campaigns like Operation Ghost, which targeted US government and political organizations post the 2016 election. Their modus operandi typically involves phishing emails with malware payloads to gain unauthorized access to systems, followed by lateral movement and data exfiltration. APT29 is known for maintaining long-term persistence within networks to gather extensive intelligence over time.

IOC Patterns

  • Spear-phishing email campaigns
  • Malware distribution via Office documents
  • Scheduled task creation
  • Registry modification for persistence

Recommended Actions

  • Implement multi-layered email filtering to detect phishing attempts.
  • Monitor for known APT29-related IOC patterns in network traffic.
  • Enhance endpoint detection and response capabilities.
  • Regularly update software and patch vulnerabilities to mitigate exploitation.

Suggested Tags

APT
Government Targeting
Espionage
Nation-State

Confidence Assessment

Confidence in APT29's activities is high due to extensive evidence from tracked campaigns and technical details. However, gaps exist in fully understanding their exact methods and long-term objectives.

ATT&CK Techniques

Command & Control
11 techniques
Credential Access
10 techniques
Execution
11 techniques
Initial Access
6 techniques
Persistence
11 techniques
Resource Development
10 techniques
Stealth
13 techniques

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 5 MD5 Hash 8 Filename 2 Domain 5

References

  1. Crowdstrike DNC June 2016 — Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.
  2. Volexity SolarWinds — Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020.
  3. CrowdStrike SUNSPOT Implant January 2021 — CrowdStrike Intelligence Team. (2021, January 11). SUNSPOT: An Implant in the Build Process. Retrieved January 11, 2021.
  4. CrowdStrike StellarParticle January 2022 — CrowdStrike. (2022, January 27). Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign. Retrieved February 7, 2022.
  5. GRIZZLY STEPPE JAR — Department of Homeland Security and Federal Bureau of Investigation. (2016, December 29). GRIZZLY STEPPE – Russian Malicious Cyber Activity. Retrieved January 11, 2017.
  6. FireEye APT29 Nov 2018 — Dunwoody, M., et al. (2018, November 19). Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign. Retrieved November 27, 2018.
  7. F-Secure The Dukes — F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.
  8. ESET Dukes October 2019 — Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.
  9. FireEye SUNBURST Backdoor December 2020 — FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.
  10. SentinelOne NobleBaron June 2021 — Guerrero-Saade, J. (2021, June 1). NobleBaron | New Poisoned Installers Could Be Used In Supply Chain Attacks. Retrieved August 4, 2021.
  11. Mandiant APT29 Eye Spy Email Nov 22 — Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023.
  12. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  13. Microsoft Unidentified Dec 2018 — Microsoft Defender Research Team. (2018, December 3). Analysis of cyberattack on U.S. think tanks, non-profits, public sector by unidentified attackers. Retrieved April 15, 2019.
  14. MSTIC NOBELIUM May 2021 — Microsoft Threat Intelligence Center (MSTIC). (2021, May 27). New sophisticated email-based attack from NOBELIUM. Retrieved May 28, 2021.
  15. MSRC Nobelium June 2021 — MSRC. (2021, June 25). New Nobelium activity. Retrieved August 4, 2021.
  16. MSTIC Nobelium Toolset May 2021 — MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.
  17. MSTIC NOBELIUM Mar 2021 — Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.
  18. NCSC APT29 July 2020 — National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020.
  19. Cybersecurity Advisory SVR TTP May 2021 — NCSC, CISA, FBI, NSA. (2021, May 7). Further TTPs associated with SVR cyber actors. Retrieved July 29, 2021.
  20. NSA Joint Advisory SVR SolarWinds April 2021 — NSA, FBI, DHS. (2021, April 15). Russian SVR Targets U.S. and Allied Networks. Retrieved April 16, 2021.
  21. PWC WellMess C2 August 2020 — PWC. (2020, August 17). WellMess malware: analysis of its Command and Control (C2) server. Retrieved September 29, 2020.
  22. PWC WellMess July 2020 — PWC. (2020, July 16). How WellMess malware has been used to target COVID-19 vaccines. Retrieved September 24, 2020.
  23. Secureworks IRON HEMLOCK Profile — Secureworks CTU. (n.d.). IRON HEMLOCK. Retrieved February 22, 2022.
  24. Secureworks IRON RITUAL Profile — Secureworks CTU. (n.d.). IRON RITUAL. Retrieved February 24, 2022.
  25. UK Gov Malign RIS Activity April 2021 — UK Gov. (2021, April 15). UK and US expose global campaign of malign activity by Russian intelligence services . Retrieved April 16, 2021.
  26. UK Gov UK Exposes Russia SolarWinds April 2021 — UK Gov. (2021, April 15). UK exposes Russian involvement in SolarWinds cyber compromise . Retrieved April 16, 2021.
  27. UK NSCS Russia SolarWinds April 2021 — UK NCSC. (2021, April 15). UK and US call out Russia for SolarWinds compromise. Retrieved April 16, 2021.
  28. Unit 42 SolarStorm December 2020 — Unit 42. (2020, December 23). SolarStorm Supply Chain Attack Timeline. Retrieved March 24, 2023.
  29. White House Imposing Costs RU Gov April 2021 — White House. (2021, April 15). Imposing Costs for Harmful Foreign Activities by the Russian Government. Retrieved April 16, 2021.
  30. www.kaspersky.com — Cited by web research for: CozyBear
  31. cloud.google.com — Cited by web research for: ROOTSAW
  32. attack.mitre.org — Cited by web research for: T1059
  33. apt.etda.or.th — Cited by web research for: BEATDROP
  34. www.huntress.com — Cited by web research for: Phishing emails

Intel Summary

97

Techniques

67

Tools

1

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Government Targeting
Espionage
Nation-State

Details

MITRE ID
G0016
Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
70%
Added
Jul 21, 2026
STIX ID
intrusion-set--899ce53f-13a0-479b-a0e4-67d46e241542
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.