Threat Actor ๐Ÿ‡ท๐Ÿ‡บ Russia

APT29

Also known as: Group 100 ยท COZY BEAR ยท The Dukes ยท Minidionis ยท SeaDuke ยท YTTRIUM ยท IRON HEMLOCK ยท Grizzly Steppe ยท G0016 ยท ATK7 ยท Cloaked Ursa ยท TA421 ยท Blue Kitsune ยท ITG11 ยท BlueBravo ยท Nobelium ยท UAC-0029

A 2015 report by F-Secure describe APT29 as: 'The Dukes are a well-resourced, highly dedicated and organized cyberespionage group that we believe has been working for the Russian Federation since at least 2008 to collect intelligence in support of foreign and security policy decision-making. The Dukes show unusual confidence in their ability to continue successfully compromising their targets, as well as in their ability to operate with impunity. The Dukes primarily target Western governments and related organizations, such as government ministries and agencies, political think tanks, and governmental subcontractors. Their targets have also included the governments of members of the Commonwealth of Independent States;Asian, African, and Middle Eastern governments;organizations associated with Chechen extremism;and Russian speakers engaged in the illicit trade of controlled substances and drugs. The Dukes are known to employ a vast arsenal of malware toolsets, which we identify as MiniDuke, CosmicDuke, OnionDuke, CozyDuke, CloudDuke, SeaDuke, HammerDuke, PinchDuke, and GeminiDuke. In recent years, the Dukes have engaged in apparently biannual large - scale spear - phishing campaigns against hundreds or even thousands of recipients associated with governmental institutions and affiliated organizations. These campaigns utilize a smash - and - grab approach involving a fast but noisy breakin followed by the rapid collection and exfiltration of as much data as possible.If the compromised target is discovered to be of value, the Dukes will quickly switch the toolset used and move to using stealthier tactics focused on persistent compromise and long - term intelligence gathering. This threat actor targets government ministries and agencies in the West, Central Asia, East Africa, and the Middle East; Chechen extremist groups; Russian organized crime; and think tanks. It is suspected to be behind the 2015 compromise of unclassified networks at the White House, Department of State, Pentagon, and the Joint Chiefs of Staff. The threat actor includes all of the Dukes tool sets, including MiniDuke, CosmicDuke, OnionDuke, CozyDuke, SeaDuke, CloudDuke (aka MiniDionis), and HammerDuke (aka Hammertoss). '

Indicators of Compromise 22

MITRE ATT&CK TTPs 27

Source Articles

Identity Abuse Through Trusted Communication Channels
Threat actors are increasingly exploiting trusted enterprise collaboration platforms such as Microsoft Teams and Slack to conduct identity phishing, impersonation, credential theft, and malware delivery. These attacks leverage the inherent trust in authenticated communication channels to bypass traditional security controls, using techniques like external federation abuse, social engineering, and malicious third-party integrations. Real-world incidents include APT29 using compromised Teams accounts to distribute credential-harvesting links, a North Korea-linked campaign impersonating Fireblocks during fake job interviews to deliver malware via npm install, and attackers poisoning the Axios npm package by compromising a maintainer through a spoofed Slack environment. Additionally, attackers have used legitimate Slack webhook integrations on compromised appliances to exfiltrate credentials, demonstrating post-compromise persistence through trusted SaaS channels.
unit42 ยท1w ago
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has identified a global campaign dubbed CaptiveCrunch, attributed to the Russian threat actor Midnight Blizzard (also known as APT29 or Storm-2945), targeting hotel and conference center Wi-Fi networks. The attackers manipulate DNS settings on captive portal equipment to redirect users to phishing pages impersonating Microsoft 365 login portals or abusing Microsoft Entra ID device code authentication flows. They also deploy custom malware, including the Go-based RAT CornFlake and the PowerShell-based ChocoShell, to steal credentials, session tokens, and conduct surveillance. A previously undisclosed tactic involves fake OS and browser update prompts (ClickFix) delivering malware to Windows and Android devices.
bleeping-computer ยท4w ago
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A threat actor dubbed Storm-2945, assessed to be a sub-cluster of the Russian state-sponsored group APT29 (aka Cozy Bear), has hijacked hotel Wi-Fi networks to deliver a surveillance-focused remote access trojan named CornFlake. The attack abuses compromised captive portals to redirect users to fake browser or OS update prompts, which lead to the download of malicious payloads. The CornFlake malware, written in Go, establishes persistence via registry run keys and scheduled tasks, captures keystrokes, screenshots, microphone audio, and browser credentials, and can bypass Chrome's App-Bound Encryption. A related in-memory PowerShell stealer, ChocoShell, harvests Microsoft 365, Azure AD, and WAM tokens from the Token Broker cache. Attackers also leveraged Microsoft's device code authentication flow to gain MFA-satisfied access by tricking users into approving malicious sessions.
hacker-news ยท4w ago
PlugX Meeting Invitation via MSBuild and GDATA
A recent PlugX RAT campaign leverages a spear-phishing email with the subject 'Meeting Invitation' to deliver malicious payloads via DLL side-loading. The infection chain uses a legitimate G DATA antivirus executable (Avk.exe) to load a malicious DLL (Avk.dll), which decrypts and executes the payload from AVKTray.dat. The malware establishes persistence through a registry Run key and communicates with the C2 server at decoorat[.]net over HTTPS on port 443. The campaign demonstrates continued use of trusted binaries, XOR-based obfuscation, and API hashing techniques consistent with China-aligned threat actors.
lab52 ยท6mo ago
Zimbra urges customers to patch critical web client XSS flaw
Zimbra has urged customers to patch a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via specially crafted emails. The flaw affects Zimbra Collaboration Suite users and could lead to theft of session data, account settings, or mailbox contents. Although no CVE has been assigned yet, the vulnerability was reported by Google's Threat Analysis Group and is suspected to be exploited by state-backed actors, particularly Russian-linked groups.
bleeping-computer ยท1mo ago