APT29
Russian state-sponsored (SVR) · Espionage / intelligence collection / supply chain access
Tactics, Techniques & Procedures (TTPs)
- Supply chain compromise (SolarWinds Orion, IT service providers)
- OAuth application abuse for persistent cloud tenant access
- Residential proxy networks for detection evasion
- WINELOADER and ROOTSAW staged downloaders
- Dormant account reactivation in cloud directories
- Cloud management plane lateral movement
Known Targets
Analyst Notes
SVR Foreign Intelligence Service. The SolarWinds Orion supply chain compromise (2020) affected approximately 18,000 organisations and provided access to multiple US federal agencies. Compromised Microsoft senior leadership email in January 2024 while actively searching for information about APT29 detection capabilities — a sophisticated counter-intelligence operation.
Also Known As
Intelligence Reports
Midnight Blizzard: A Complete Profile of Russia's SVR Espionage Apparatus
APT29 — Cozy Bear, Midnight Blizzard — is Russia's SVR-aligned intelligence collection machine, responsible for SolarWinds, the 2024 Microsoft corporate email compromise, and ongoing targeting of European governments, diplomatic missions, and defence industrial base organisations. This deep dive covers their full operational history, tradecraft, tooling, and what defenders need to be doing now.
APT29 Exploiting Trusted Vendor Relationships to Reach UK and European Government Networks
Russia's SVR-linked APT29 is using compromised software vendor and IT service provider accounts to pivot into government targets -- a continuation of the SolarWinds playbook applied to UK and European supply chains.