
THREAT‑WATCH
Threat Actors
APT29
Cozy Bear, Midnight Blizzard, Nobelium
A cyberespionage group widely attributed by Western governments to Russia's foreign intelligence service (SVR), known for patient, stealthy, long-term intrusions.
APT29 is generally considered one of the most technically sophisticated state-sponsored groups, favoring quiet, long-term access over disruptive attacks. It was publicly attributed to the 2020 SolarWinds supply chain compromise, which affected thousands of organizations including multiple US government agencies, by inserting malicious code into a legitimate software update. Its operations typically prioritize intelligence collection and go to significant lengths to avoid detection over long periods.
Target Sectors
Government agencies, think tanks, and technology/software supply chains, with a pattern of targeting organizations that provide onward access to further targets.