G0016

G0016APT29

Description

[APT29](https://attack.mitre.org/groups/G0016) is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).(Citation: White House Imposing Costs RU Gov April 2021)(Citation: UK Gov Malign RIS Activity April 2021) They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. [APT29](https://attack.mitre.org/groups/G0016) reportedly compromised the Democratic National Committee starting in the summer of 2015.(Citation: F-Secure The Dukes)(Citation: GRIZZLY STEPPE JAR)(Citation: Crowdstrike DNC June 2016)(Citation: UK Gov UK Exposes Russia SolarWinds April 2021) In April 2021, the US and UK governments attributed the [SolarWinds Compromise](https://attack.mitre.org/campaigns/C0024) to the SVR; public statements included citations to [APT29](https://attack.mitre.org/groups/G0016), Cozy Bear, and The Dukes.(Citation: NSA Joint Advisory SVR SolarWinds April 2021)(Citation: UK NSCS Russia SolarWinds April 2021) Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.(Citation: FireEye SUNBURST Backdoor December 2020)(Citation: MSTIC NOBELIUM Mar 2021)(Citation: CrowdStrike SUNSPOT Implant January 2021)(Citation: Volexity SolarWinds)(Citation: Cybersecurity Advisory SVR TTP May 2021)(Citation: Unit 42 SolarStorm December 2020)

References

  1. https://attack.mitre.org/groups/G0016
  2. https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/
  3. https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/
  4. https://www.crowdstrike.com/blog/sunspot-malware-technical-analysis/
  5. https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/
  6. https://www.us-cert.gov/sites/default/files/publications/JAR_16-20296A_GRIZZLY%20STEPPE-2016-1229.pdf
  7. https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy-an-uncomfortable-examination-of-a-suspected-apt29-phishing-campaign.html
  8. https://www.f-secure.com/documents/996508/1030745/dukes_whitepaper.pdf
  9. https://www.welivesecurity.com/wp-content/uploads/2019/10/ESET_Operation_Ghost_Dukes.pdf
  10. https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html

Software attributed to this22

TypeTargetConfidenceTier
SoftwareWellMesss0514100%live
SoftwareOnionDukes0052100%live
SoftwareLiteDukes0513100%live
SoftwareFoggyWebs0661100%live
SoftwarePowerDukes0139100%live
SoftwareVaporRages0636100%live
SoftwareSibots0589100%live
SoftwareGoldMaxs0588100%live
SoftwareNativeZones0637100%live
SoftwareCosmicDukes0050100%live
SoftwareCozyCars0046100%live
SoftwareHAMMERTOSSs0037100%live
SoftwareGeminiDukes0049100%live
SoftwareWellMails0515100%live
SoftwareMiniDukes0051100%live
SoftwareSUNSPOTs056295%live
SoftwareFatDukes051295%live
SoftwareGoldFinders059795%live
SoftwareTEARDROPs056095%live
SoftwareQUIETEXITs108495%live
SoftwareRaindrops056595%live
SoftwareBoomBoxs063595%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
APT28
Campaign
SolarWinds Compromise
Group
UNC2452
Group
APT17
Actor
APT30
Group
Sandworm Team
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.