LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0016: APT29

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).CitationWhite House Imposing Costs RU Gov April 2021CitationUK Gov Malign RIS Activity April 2021 They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015.CitationF-Secure The DukesCitationGRIZZLY STEPPE JARCitationCrowdstrike DNC June 2016CitationUK Gov UK Exposes Russia SolarWinds April 2021

In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes.CitationNSA Joint Advisory SVR SolarWinds April 2021CitationUK NSCS Russia SolarWinds April 2021 Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.CitationFireEye SUNBURST Backdoor December 2020CitationMSTIC NOBELIUM Mar 2021CitationCrowdStrike SUNSPOT Implant January 2021CitationVolexity SolarWindsCitationCybersecurity Advisory SVR TTP May 2021CitationUnit 42 SolarStorm December 2020

EnterpriseG0016GroupObject v6.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

APT29 is a high-priority threat group profile because ATT&CK ties it to long-running espionage activity, government and research targeting, and the SolarWinds supply-chain compromise. For leaders, the decision value is not the name alone; it is whether identity systems, software supply chains, email defenses, endpoint monitoring, and incident response playbooks can withstand stealthy access, credential theft, API abuse, and use of legitimate administrative tools.

Executive priority

Treat this object as a strategic readiness benchmark for advanced intrusion scenarios. The supplied relationships point to risk areas that materially affect business continuity and audit defensibility: third-party software trust, build/update integrity, Windows credential exposure, privileged remote execution, cloud or API activity review, and phishing-driven initial access. Executives should ask whether the organization can prove coverage across identity, endpoint, email, network egress, and software supply-chain monitoring rather than relying on attribution labels after an incident.

Technical view

ATT&CK does not provide a detection section, platforms, or tactics for the group itself, so defenders should validate coverage through the related campaigns and software. The relationships show use of credential dumping tooling such as Mimikatz, remote execution and administration utilities such as PsExec and Net, discovery utilities such as Tasklist, Systeminfo, and ipconfig, multiple APT29-associated Windows backdoors, and cross-platform tools or anonymization components including Cobalt Strike, Tor, and meek. The SolarWinds campaign relationship also highlights password spraying, token theft, API abuse, spear phishing, and compromise of a software build/update process as areas for defensive validation.

Likely telemetry

  • Identity provider and directory authentication logs, especially failed login patterns consistent with password spraying and successful use after failures.
  • Token, session, OAuth/API, and cloud or SaaS audit logs where available, because the SolarWinds relationship includes token theft and API abuse.
  • Endpoint process creation, command-line, module load, credential access, service creation, and remote execution telemetry on Windows systems.
  • EDR/AV detections and file/process evidence for named malware and tools related to this group, including Mimikatz, PsExec, Cobalt Strike, and APT29-associated backdoors.
  • Email security, attachment, macro, and user-reporting telemetry relevant to spear phishing and document-based delivery noted in related software descriptions.

Detection direction

  • Because ATT&CK provides no official detection text for this group, build detections from the related behaviors and tools rather than from the group name alone.
  • Correlate identity anomalies with endpoint execution and network egress; password spraying, token misuse, and API abuse may not be visible in endpoint-only monitoring.
  • Tune carefully for dual-use tools such as PsExec, Net, Tasklist, Systeminfo, ipconfig, SDelete, Cobalt Strike, Tor, and meek. Baseline legitimate administrative use, then alert on abnormal users, hosts, timing, destinations, or privilege context.
  • Prioritize credential-theft visibility around Windows endpoints and privileged accounts because Mimikatz is a related software object.
  • Validate detections for remote execution and lateral administration, especially service creation, SMB/admin share activity, and command execution patterns associated with legitimate tools used outside approved workflows.

Mitigation priorities

  • Start with identity controls: enforce strong authentication for privileged and remote access, monitor password spraying indicators, and reduce token/session exposure where feasible.
  • Harden privileged Windows environments by limiting credential material exposure, restricting administrative tool use, and monitoring remote execution paths.
  • Control and monitor email-based delivery paths, including document attachments and macro-enabled content where business policy allows.
  • Strengthen egress governance and logging so unusual HTTPS tunneling, anonymization, or web-service-based command-and-control patterns can be investigated.
  • Improve software supply-chain assurance for critical products and internal build systems, including access control, change control, signing governance, and artifact integrity review.
Additional notes and limits

This take is based on the official ATT&CK APT29 group object, its aliases, external references, and supplied relationships to campaigns and software. The most decision-relevant relationship is the SolarWinds Compromise, which links this group to supply-chain compromise and identity/API-related activity. The software relationships also show a mix of custom malware, credential theft, discovery utilities, administrative tools, anonymization software, and post-exploitation tooling.

The group object has no official ATT&CK detection text, no listed tactics, and no group-level platforms. Platform references in this take come only from related software objects and should not be interpreted as complete platform coverage. Local telemetry, architecture, cloud providers, identity design, and administrative practices are required to determine real exposure or detection maturity.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

APT29

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).CitationWhite House Imposing Costs RU Gov April 2021CitationUK Gov Malign RIS Activity April 2021 They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015.CitationF-Secure The DukesCitationGRIZZLY STEPPE JARCitationCrowdstrike DNC June 2016CitationUK Gov UK Exposes Russia SolarWinds April 2021

In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes.CitationNSA Joint Advisory SVR SolarWinds April 2021CitationUK NSCS Russia SolarWinds April 2021 Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.CitationFireEye SUNBURST Backdoor December 2020CitationMSTIC NOBELIUM Mar 2021CitationCrowdStrike SUNSPOT Implant January 2021CitationVolexity SolarWindsCitationCybersecurity Advisory SVR TTP May 2021CitationUnit 42 SolarStorm December 2020

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
6.2
Created
Modified
Raw hash
66bfb5ded9ef751f...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.