APT29, known as Cozy Bear or Midnight Blizzard and linked to Russia’s SVR, is a sophisticated espionage group behind the SolarWinds compromise and ongoing cloud and identity-based intrusions.
Key facts
- Attributed to Russia’s foreign intelligence service (SVR).
- Responsible for the 2020 SolarWinds supply-chain compromise.
- Has shifted toward identity-based access: credential theft, token abuse and cloud account compromise.
- Targets diplomatic, government and technology organisations.
Why it matters
APT29 increasingly attacks identities and cloud accounts rather than perimeters. Detecting leaked credentials and session theft is central to stopping them.
How DarkThreatX helps
DarkThreatX tracks threat-actor activity, leaked credentials and exposed data across the dark web so security teams can act on early warning. Run a free dark web scan or explore the platform.