Storm-2945
MITRE G0016Also known as CaptiveCrunch, Cozy Bear
Reports
4
First seen
Jul 31, 2026
Last seen
Aug 3, 2026
Motivation
Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Top ATT&CK techniques
T1566 Phishing ×4T1003 OS Credential Dumping ×3T1059 Command and Scripting Interpreter ×2T1053 Scheduled Task/Job ×2T1041 Exfiltration Over C2 Channel ×2T1219 Remote Access Software ×2T1598 Phishing for Information ×2T1056 Input Capture ×2T1547.001 Registry Run Keys / Startup Folder ×2T1543.003 Create or Modify System Process: Windows Service ×2T1110 Brute Force ×1T1195 Supply Chain Compromise ×1
Indicators
domain ×14filename ×12ip_v4 ×8cve ×7url ×5registry_key ×3hash_sha256 ×2
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High