MITRE ATT&CK G0016
Aliases: Cozy Bear, Nobelium, Midnight Blizzard, The Dukes, SVR
Official Attribution Source: CISA Advisory AA20-352A & White House Statement
Key Facts
Jurisdiction
Russian Federation
Geographic origin
Cases
1
Prosecution matters
Defendants
0
Indicted individuals
Sanctions
0
OFAC designations
- Attributed Country: Russian Federation.
- ATT&CK Group Reference: G0016 (APT29).
- Linked to 1 primary court prosecution records.
- Identified 0 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1190 Exploit Public-Facing Application | 1 incidents |
| T1071.001 Web Protocols | 1 incidents |
| T1078 Valid Accounts | 1 incidents |
| T1132 Data Encoding | 1 incidents |
| T1036 Masquerading | 1 incidents |
Prosecution Cases Attributed to This Actor
alleged 2020-12-13
SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)
Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.
5 techniques
View case →