APT29
MITRE G0016Also known as Midnight Blizzard, Cloaked Ursa, BlueBravo, Cozy Bear, Storm-2945
Reports
11
First seen
Oct 3, 2024
Last seen
Aug 4, 2026
Motivation
Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Victim regions
×2×2
United States×2
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1566 Phishing ×9T1598 Phishing for Information ×4T1190 Exploit Public-Facing Application ×4T1059.001 PowerShell ×3T1041 Exfiltration Over C2 Channel ×3T1547 Boot or Logon Autostart Execution ×3T1078 Valid Accounts ×3T1110 Brute Force ×2T1598.003 Spearphishing Link ×2T1003 OS Credential Dumping ×2T1589 Gather Victim Identity Information ×2T1055 Process Injection ×2
Indicators
cve ×99domain ×12url ×3filename ×2ip_v4 ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2019-5736 (exploited)CVE-2022-0492 (exploited)CVE-2024-21626 (exploited)CVE-2025-20333 (exploited)CVE-2025-20352 (exploited)CVE-2025-20362 (exploited)CVE-2025-43300 (exploited)CVE-2025-48700 (exploited)CVE-2025-55177 (exploited)CVE-2025-55241CVE-2025-66376 (exploited)CVE-2026-20230CVE-2026-26980 (exploited)CVE-2026-27771CVE-2026-42897 (exploited)CVE-2026-42945 (exploited)CVE-2026-51296CVE-2026-51297CVE-2026-51300CVE-2026-51302
Recent reports
High