Avatier

Threat actor

APT29

Also known as Midnight BlizzardSource [1], the DukesSource [1], Cozy BearSource [1]

The UK NCSC and international partners assess that APT29 is a cyber espionage group, almost certainly part of Russia's SVR intelligence service; NSA, CISA, the FBI and others agree with this attribution.Source [1]

What authorities and investigators report

  • The advisory says SVR campaigns used brute forcing and password spraying to access service accounts, which have no human user behind them and so cannot easily be protected with MFA.Source [1]
  • It says SVR campaigns targeted dormant accounts of users who no longer worked at the victim organization, and that after an enforced password reset the actors logged into inactive accounts and followed the reset instructions.Source [1]
  • It says SVR actors used tokens to access victims' accounts without needing a password.Source [1]
  • It says SVR actors bypassed MFA by repeatedly pushing MFA requests to a victim's device until the victim accepted, then registered their own device on the cloud tenant.Source [1]
  • The advisory says SVR actors are also known for the supply chain compromise of SolarWinds software.Source [1]
  • The NCSC said it had observed SVR actors expanding their targeting to include aviation, education, law enforcement, local and state councils, government financial departments and military organizations.Source [1]

Techniques

Attack vectors

Sources

  1. SVR Cyber Actors Adapt Tactics for Initial Cloud Access (AA24-057A) — CISA, 2024-02-26

Last reviewed Oct 2, 2026