Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ APT29

🇷🇺APT29

🇷🇺 APT29 is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: State. We map 24 detection use cases to this actor across 104 MITRE ATT&CK techniques, with 7 threat-intel articles citing them. Active in our corpus from 2026-02-26 to 2026-08-10.

crit 6low 1
View full actor card → All threat actors MITRE ATT&CK group spec (G0016) ↗
24Use cases
7Articles
104Techniques
46IOCs

Known aliases

APT29Cozy BearNobeliumMidnight BlizzardThe DukesYTTRIUMSVRIRON RITUALIRON HEMLOCKNobleBaronDark HaloNOBELIUMUNC2452CozyDukeSolarStormBlue KitsuneUNC3524

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.002 · Security Account ManagerT1003.003 · NTDST1003.004 · LSA SecretsT1005 · Data from Local SystemT1016.001 · Internet Connection DiscoveryT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1021.007 · Cloud ServicesT1027 · Obfuscated Files or InformationT1027.001 · Binary PaddingT1027.002 · Software PackingT1027.006 · HTML SmugglingT1036.005 · Match Legitimate Resource Name or LocationT1037 · Boot or Logon Initialization ScriptsT1037.004 · RC ScriptsT1047 · Windows Management InstrumentationT1053.005 · Scheduled TaskT1057 · Process DiscoveryT1059 · Command and Scripting InterpreterT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.006 · PythonT1059.007 · JavaScriptT1059.009 · Cloud APIT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1078 · Valid AccountsT1078.003 · Local AccountsT1078.004 · Cloud AccountsT1087.004 · Cloud AccountT1090.002 · External ProxyT1090.003 · Multi-hop ProxyT1090.004 · Domain FrontingT1098.001 · Additional Cloud CredentialsT1098.002 · Additional Email Delegate PermissionsT1098.005 · Device RegistrationT1105 · Ingress Tool TransferT1110.001 · Password GuessingT1110.003 · Password SprayingT1112 · Modify RegistryT1114.002 · Remote Email CollectionT1127.001 · MSBuildT1133 · External Remote ServicesT1136.003 · Cloud AccountT1176 · Software ExtensionsT1195.001 · Compromise Software Dependencies and Development ToolsT1195.002 · Compromise Software Supply ChainT1199 · Trusted RelationshipT1203 · Exploitation for Client ExecutionT1204 · User ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1218.005 · MshtaT1218.011 · Rundll32T1219 · Remote Access ToolsT1486 · Data Encrypted for ImpactT1505.003 · Web ShellT1528 · Steal Application Access TokenT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1546.003 · Windows Management Instrumentation Event SubscriptionT1546.008 · Accessibility FeaturesT1547.001 · Registry Run Keys / Startup FolderT1548.002 · Bypass User Account ControlT1550.003 · Pass the TicketT1552.001 · Credentials In FilesT1552.005 · Cloud Instance Metadata APIT1553.005 · Mark-of-the-Web BypassT1554 · Compromise Host Software BinaryT1555.003 · Credentials from Web BrowsersT1556.007 · Hybrid IdentityT1557 · Adversary-in-the-MiddleT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1566.003 · Spearphishing via ServiceT1567.002 · Exfiltration to Cloud StorageT1568 · Dynamic ResolutionT1569.002 · Service ExecutionT1573 · Encrypted ChannelT1573.002 · Asymmetric CryptographyT1574.002 · T1574.002T1583.006 · Web ServicesT1586.002 · Email AccountsT1586.003 · Cloud AccountsT1587.001 · MalwareT1587.003 · Digital CertificatesT1588.002 · ToolT1595.002 · Vulnerability ScanningT1621 · Multi-Factor Authentication Request GenerationT1649 · Steal or Forge Authentication CertificatesT1651 · Cloud Administration CommandT1665 · Hide InfrastructureT1685.002 · Disable or Modify Cloud Log

Detection use cases (24)

Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Remote service execution — PsExec / SMB lateral movement Internal PowerShell encoded / obfuscated command Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal Network connections to article IPs / domains Internal File hash IOCs — endpoint file/process match Internal Article-specific behavioural hunt — DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized rec Internal Beaconing — periodic outbound to small set of destinations Internal 1Password activity from Tor exit node MITRE match 1Password impossible-travel sign-in MITRE match AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation MITRE match AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process MITRE match AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request MITRE match Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) MITRE match Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection MITRE match

Threat-intel articles (7)

Tracked indicators

Domains (40)

1rpc.io applefilevault.com apricotfilepoint.com bananafastfile.com cloudfilebridge.com cloudsendhub.com deadblogdbdu5wprek7wa2o4 deadlock.liveblog365.com deadlockblog.great-site. deadlockblog.medianewson decoorat.net decoraat.net dlock.liveblog365.com filecedarwallet.online filecopperbasket.sbs filecrimsonsignal.online filemarblegarden.sbs fileoceanhammer.sbs filerubyfolder.sbs filevelvettractor.sbs gesecole.net js-mirror.com lemonfilewave.com limefilescope.com m365-owa.com +15 more

IP addresses (6)

104.194.159.150 107.189.26.194 213.145.86.112 31.57.243.154 38.146.28.132 38.146.28.75