Skip to content
Auto-CTI
Back to all actors

APT29

Nation-state Espionage Russia Active

Aliases: Cozy Bear · Nobelium · Midnight Blizzard · The Dukes · Cozy Duke · UNC2452 · Cloaked Ursa

Also seen as: NOBELIUM

Mentions
2
First seen
22 May 2026
Last seen
11 Sept 2026

Relevant to you · Relevant

Threat focus:
espionage / aptindustrial / ot espionage
Sector / region:
Manufacturing

Origin

Russia — Russian foreign intelligence (SVR)

Profile

APT29 is a Russian state-sponsored hacking group. According to recent headlines, the group uses Claude to rebuild malware after detection. Additionally, APT29 is associated with ROADtools and nation-state tactics in the cloud.

Affected vendors

Microsoft

Associated malware / tools

ROADtools

Activity (8 weeks)

31
32
33
34
35
36
37
38

Recent activity

ESC