Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0016
MITRE ATT&CK Group

APT29 (G0016)

IRON RITUALIRON HEMLOCKNobleBaronDark HaloNOBELIUMUNC2452YTTRIUMThe DukesCozy BearCozyDukeSolarStormBlue KitsuneUNC3524Midnight Blizzard
ShareXLinkedInRedditHN

[APT29](https://attack.mitre.org/groups/G0016) is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).(Citation: White House Imposing Costs RU Gov April 2021)(Citation: UK Gov Malign RIS Activity April 2021) They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. [APT29](https://attack.mitre.org/groups/G0016) reportedly compromised the Democratic National Committee starting in the summer of 2015.(Citation: F-Secure The Dukes)(Citation: GRIZZLY STEPPE JAR)(Citation: Crowdstrike DNC June 2016)(Citation: UK Gov UK Exposes Russia SolarWinds April 2021) In April 2021, the US and UK governments attributed the [SolarWinds Compromise](https://attack.mitre.org/campaigns/C0024) to the SVR; public statements included citations to [APT29](https://attack.mitre.org/groups/G0016), Cozy Bear, and The Dukes.(Citation: NSA Joint Advisory SVR SolarWinds April 2021)(Citation: UK NSCS Russia SolarWinds April 2021) Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.(Citation: FireEye SUNBURST Backdoor December 2020)(Citation: MSTIC NOBELIUM Mar 2021)(Citation: CrowdStrike SUNSPOT Implant January 2021)(Citation: Volexity SolarWinds)(Citation: Cybersecurity Advisory SVR TTP May 2021)(Citation: Unit 42 SolarStorm December 2020)

▪Techniques used (66)

T1621Multi-Factor Authentication Request GenerationT1003.002Security Account ManagerT1588.002ToolT1090.004Domain FrontingT1528Steal Application Access TokenT1568Dynamic ResolutionT1068Exploitation for Privilege EscalationT1546.003Windows Management Instrumentation Event SubscriptionT1547.001Registry Run Keys / Startup FolderT1136.003Cloud AccountT1098.005Device RegistrationT1587.003Digital CertificatesT1005Data from Local SystemT1105Ingress Tool TransferT1651Cloud Administration CommandT1566.001Spearphishing AttachmentT1078.004Cloud AccountsT1053.005Scheduled TaskT1016.001Internet Connection DiscoveryT1587.001MalwareT1583.006Web ServicesT1090.003Multi-hop ProxyT1037Boot or Logon Initialization ScriptsT1027.006HTML SmugglingT1070.004File DeletionT1203Exploitation for Client ExecutionT1550.003Pass the TicketT1204.001Malicious LinkT1036.005Match Legitimate Resource Name or LocationT1110.003Password SprayingT1114.002Remote Email CollectionT1027.001Binary PaddingT1556.007Hybrid IdentityT1059.001PowerShellT1133External Remote ServicesT1037.004RC ScriptsT1021.007Cloud ServicesT1595.002Vulnerability ScanningT1566.002Spearphishing LinkT1070.006TimestompT1586.003Cloud AccountsT1090.002External ProxyT1573Encrypted ChannelT1047Windows Management InstrumentationT1110.001Password GuessingT1199Trusted RelationshipT1566.003Spearphishing via ServiceT1078Valid AccountsT1505.003Web ShellT1059.006PythonT1665Hide InfrastructureT1218.005MshtaT1003.004LSA SecretsT1190Exploit Public-Facing ApplicationT1553.005Mark-of-the-Web BypassT1649Steal or Forge Authentication CertificatesT1087.004Cloud AccountT1098.002Additional Email Delegate PermissionsT1078.003Local AccountsT1546.008Accessibility FeaturesT1059.009Cloud APIT1586.002Email AccountsT1204.002Malicious FileT1685.002Disable or Modify Cloud LogT1548.002Bypass User Account ControlT1027.002Software Packing

▪Software used (49)

S0048PinchDukemalwareS0684ROADToolstoolS0515WellMailmalwareS0046CozyCarmalwareS0002MimikatztoolS0175meektoolS0682TrailBlazermalwareS0057TasklisttoolS0052OnionDukemalwareS0512FatDukemalwareS0150POSHSPYmalwareS0634EnvyScoutmalwareS0516SoreFangmalwareS0049GeminiDukemalwareS1187reGeorgmalwareS0521BloodHoundtoolS0588GoldMaxmalwareS0661FoggyWebmalwareS0195SDeletetoolS0518PolyglotDukemalwareS0677AADInternalstoolS0051MiniDukemalwareS0560TEARDROPmalwareS0053SeaDukemalwareS0589SibotmalwareS0565RaindropmalwareS0511RegDukemalwareS0054CloudDukemalwareS0597GoldFindermalwareS0552AdFindtoolS0029PsExectoolS0183TortoolS0637NativeZonemalwareS0096SysteminfotoolS0100ipconfigtoolS0562SUNSPOTmalwareS0357ImpackettoolS0154Cobalt StrikemalwareS0139PowerDukemalwareS0039NettoolS1084QUIETEXITmalwareS0037HAMMERTOSSmalwareS0635BoomBoxmalwareS0633SlivertoolS0050CosmicDukemalwareS0559SUNBURSTmalwareS0514WellMessmalwareS0636VaporRagemalwareS0513LiteDukemalware
G0016on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.