Incidents
APT29
Review stories that name this actor, with reporting mentions kept distinct from attribution of an operation.
News reporting onlyThis profile is assembled only from stories in this tracker’s reporting corpus. A mention measures this tracker’s coverage and is not attribution of an operation.
Named in 11 stories by this tracker. Population: 256 news stories with stored actor tags in this tracker corpus.
Catalogued identity
These references are curated crosswalk entries, not claims made by any feed. They describe the group, not the stories above.
MITRE catalogues 66 techniques for this group.
MITRE ATT&CK names and links © The MITRE Corporation.
Stories that name this actor
- Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research
- Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter
- Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia
- CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
- Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
- Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
- [tl;dr sec] #330 - AWS Pathfinding Labs, Running Codex Safely at OpenAI, Glasswing Updates
- Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication
- Russia-Linked Threats to Operational Technology
- Midnight Blizzard attack on Microsoft corporate environment: a detailed analysis, detections and recommendations
- Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 2)