APT29
Nation-state Espionage Russia Active
Aliases: Cozy Bear · Nobelium · Midnight Blizzard · The Dukes · Cozy Duke · UNC2452 · Cloaked Ursa
Also seen as: NOBELIUM
- Mentions
- 2
- First seen
- 22 May 2026
- Last seen
- 11 Sept 2026
Relevant to you · Relevant
- Threat focus:
- espionage / aptindustrial / ot espionage
- Sector / region:
- Manufacturing
Origin
Russia — Russian foreign intelligence (SVR)
Profile
APT29 is a Russian state-sponsored hacking group. According to recent headlines, the group uses Claude to rebuild malware after detection. Additionally, APT29 is associated with ROADtools and nation-state tactics in the cloud.
Affected vendors
Microsoft
Associated malware / tools
ROADtools