← Back to all threat actors

APT29

Also known as IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard
Tracked as G0016

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015. In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.

How we source and review actor profiles
Motivation
nation-state
Attributed nexus
RU
Sectors
government, healthcare, technology, ngo, research-academia
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: IRON RITUAL

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: IRON HEMLOCK

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: NobleBaron

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Dark Halo

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: NOBELIUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: UNC2452

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: YTTRIUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: The Dukes

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Cozy Bear

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: CozyDuke

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: SolarStorm

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Blue Kitsune

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: UNC3524

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Midnight Blizzard

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0016

Reviewed identity mapping approved on this date.

Cataloged
CVECVE-2020-1472 linked to this actor
Cataloged
CVECVE-2021-26855 linked to this actor
Cataloged
CVECVE-2021-26857 linked to this actor
Cataloged
CVECVE-2021-27065 linked to this actor
Cataloged
CVECVE-2023-23397 linked to this actor
Last observed
CampaignSolarWinds Compromise

The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used custom…

Last observed
CampaignOperation Ghost

Operation Ghost was an APT29 campaign starting in 2013 that included operations against ministries of foreign affairs in Europe and the Washington, D.C. embassy of a European Union country. Duri…

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

APT29Canonical Name
Blue KitsuneAlias
Cozy BearAlias
CozyDukeAlias
Dark HaloAlias
IRON HEMLOCKAlias
IRON RITUALAlias
Midnight BlizzardAlias
NOBELIUMAlias
NobleBaronAlias
SolarStormAlias
The DukesAlias
UNC2452Alias
UNC3524Alias
YTTRIUMAlias
G0016Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...