DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-29
groupactive

Midnight Blizzard (APT29 / Nobelium / Cozy Bear)

KNOWN ALIASES: APT29 · Nobelium · Cozy Bear · The Dukes · Cloaked Ursa · StellarParticle
EXECUTIVE INTELLIGENCE SUMMARY

Elite Russian Foreign Intelligence Service (SVR) cyber espionage apparatus celebrated for high-level government infiltration, SolarWinds supply chain poisoning, and cloud token manipulation.

Demonstrates exceptional operational discipline, relying on legitimate cloud administrative features, OAuth application permissions, spray passwords against non-MFA legacy test tenants, and residential proxy networks to avoid signature detection.

MAJOR ATTRIBUTED OPERATIONS
2024 · Corporate Executive Email InfiltrationTARGET: Major Technology & Cloud Providers

Targeted password spraying against legacy non-production tenant allowing pivot into executive inboxes and source code repositories.

2020 · SolarWinds Orion Supply Chain CompromiseTARGET: SolarWinds Software Build Pipeline

Insertion of SUNBURST backdoor into signed Orion platform updates distributed to 18,000 global customers including federal departments.

SOURCE CITATIONS & ATTESTATIONS (1)
NCSC & CISA Joint Advisory on SVR Cyber Actor OperationsNCSC / CISA

SVR Cyber Actors Adapt Tactics for Cloud Infrastructure

TELEMETRY CARDID: group-midnight-blizzard
ENTITY TYPE
group
STATE JURISDICTION / ORIGIN
Russian Federation (SVR)
INDEXED TAGS
#apt#svr#cloud_identity#supply_chain#solarwinds#oauth_abuse