#apt29
⚡ The cyberattack on Azerbaijani media resources on February 20 was carried out by the Russian hacker group APT29, officials say.
Russian Hacker Group APT29 Behind Major Cyberattack on Azerbaijani Media
Expert Ramid Namazov reveals the Russian hacker group APT29 orchestrated a politically motivated cyberattack on Azerbaijani media on February 20.
united24media.com
May 3, 2025 at 8:18 AM
Russia’s #APT29 hacked legit websites—secretly redirecting ~10% of visitors into fake “Cloudflare” pages to hijack Microsoft accounts.

Amazon flagged and disrupted the campaign, but the group quickly spun up new domains. #CyberSecurity thehackernews.com/2025/08/amaz...
Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication
Amazon disrupted APT29’s June 2025 campaign exploiting Microsoft device code authentication, redirecting 10% of visitors to malicious domains.
thehackernews.com
August 29, 2025 at 9:44 PM
Roumanie : d’après Mediapart, les services secrets roumains attribuent à APT29, une unité de hackers du renseignement extérieur russe (SVR), une opération visant à favoriser le candidat pro-Kremlin Călin Georgescu aux élections présidentielles du 6 décembre dernier 1/13
May 2, 2025 at 4:41 PM
⚡ Amazon’s security intelligence unit has disrupted a cyber-espionage campaign by a Kremlin-linked hacking group.
Amazon Blocks Kremlin Cyberattack: Russian Hackers Targeted US Cloud Accounts
APT29, linked to Russia, was disrupting sensitive US entities, including universities and nonprofits, as reported by Ukraine’s CCD on September 1.
united24media.com
September 1, 2025 at 2:16 PM
Okay so... will Equation report to APT28 or APT29?
March 1, 2025 at 4:15 PM
This is philosophically adjacent to why I say “the SVR hacked the DNC” rather than “APT29 hacked the DNC”. USG came out and said APT29 = SVR ops after SolarWinds. We can just say SVR now rather than cosplay as IC analysts unless we are dealing with activity that cannot be concretely attributed.
November 7, 2025 at 10:35 PM
In this current wave of attacks, the threat actors impersonate a major European Ministry of Foreign Affairs to send out invitations to wine tasting events, prompting targets to click a web link leading to the deployment of a new backdoor called GRAPELOADER.

research.checkpoint.com/2025/apt29-p...
Renewed APT29 Phishing Campaign Against European Diplomats - Check Point Research
Check Point Research uncovers APT29 targeting European diplomatic entities with phishing attacks spreading malware Grapeloader
research.checkpoint.com
April 18, 2025 at 11:19 AM
Russian APT29 hackers hijacked Gmail accounts using app passwords—bypassing 2FA with social engineering.

They posed as the U.S. State Dept to steal access from academics and critics. #APT29 #CyberAlerts thehackernews.com/2025/06/russ...
Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign
Russian hackers used Gmail app passwords and fake State Dept. emails to access inboxes of academics.
thehackernews.com
June 19, 2025 at 6:06 PM
10/
Germany caught it:
🟥 Doppelgänger – fake news clones
🟥 Storm-1516 – deepfake factories
🟥 Matryoshka – bot-driven manipulation
🟥 APT29 – malware hacks like WINELOADER

These tools weren’t one-offs. They were templates. And we’re next.
May 8, 2025 at 5:23 PM
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29.
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29.
www.bleepingcomputer.com
August 4, 2026 at 12:17 AM
We're excited to have Ivan Kwiatkowski as a speaker!

Ivan Kwiatkowski is a security researcher and a malware analyst working on account investigations.
His talk, "When State Actors Go Mobile: APT29’s Use of Commodity Malware" details APT29.

cyberwarcon.com
November 10, 2025 at 9:13 PM
8/ Who targeted @keirgiles.bsky.social ? Enter the Google
Threat Intelligence Group w/analysis & attribution!

Great!

Our bad actors are: 🇷🇺 #UNC6293, a #Russian state-sponsored threat actor.

Google adds bonus additional low confidence association to #APT29 (that would be the #SVR).

Nice people.
June 18, 2025 at 9:17 PM
This morning, Amazon Cyber Threat Intelligence published a report about a recent watering hole attack by APT29 🇷🇺 that we discovered targeting Microsoft device code authentication. Proud of the work of the team and the chance to share this with the community! aws.amazon.com/blogs/securi...
Amazon disrupts watering hole campaign by Russia’s APT29 | Amazon Web Services
Amazon’s threat intelligence team has identified and disrupted a watering hole campaign conducted by APT29 (also known as Midnight Blizzard), a threat actor associated with Russia’s Foreign Intelligen...
aws.amazon.com
August 29, 2025 at 1:44 PM
8/ Terrifyingly, #Coruna isn't even the first time commercially-developed hacking capabilities go to hostile actors.

Like how exploits first used by #NSOGroup's Pegasus & #Intellexa's Predator mysteriously found their way to Russian gov hackers...

blog.google/threat-analy...
State-backed attackers and commercial surveillance vendors repeatedly use the same exploits
We’re sharing an update on suspected state-backed attacker APT29 and the use of exploits identical to those used by Intellexa and NSO.
blog.google
March 10, 2026 at 4:25 AM
Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign
Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign
thehackernews.com
June 19, 2025 at 9:20 AM
Russia-linked APT29 targets European diplomatic entities with GRAPELOADER malware
Russia-linked APT29 targets European diplomatic entities with GRAPELOADER
Russia-linked group APT29 targeted diplomatic entities across Europe with a new malware loader codenamed GRAPELOADER.
securityaffairs.com
April 21, 2025 at 12:06 PM
Self-confessed APT29 member tries to spin the facts... ok...

/s
May 29, 2026 at 4:33 PM
The SolarWinds hack in 2020 was a classic example of a daisy-chain cyber attack. The Russian-backed APT29 (Cozy Bear) infiltrated SolarWinds’ Orion software, which was widely used by U.S. government agencies and major corporations. /5
February 2, 2025 at 6:48 PM
Today, Mandiant, in collaboration with Google’s TAG, is releasing research on APT29’s increased pace of phishing activity against governments, foreign embassies, and other diplomatic entities in 2023. Happy reading!

www.mandiant.com/resources/bl...
Backchannel Diplomacy: APT29’s Rapidly Evolving Diplomatic Phishing Operations
APT29’s pace of operations and emphasis on Ukraine increased in the first half of 2023.
www.mandiant.com
September 22, 2023 at 2:32 PM
This reads like data obtained by AIVD’s compromise of APT29/COZY BEAR/SVR following the downing of Malaysia Airlines Flight 17 (per Tim Weiner’s The Mission)
July 23, 2025 at 3:50 PM
➡️ Riposte russe

Face à cette tentative d’humiliation, Moscou a alors riposté en réalisant, selon Bakou, des attaques informatiques via le groupe APT29 – lié au FSB – contre des médias Azerbaïdjanais. Pour le Kremlin, c’est une manière de riposter et de menacer l’Azerbaïdjan.

10/22
July 3, 2025 at 2:56 PM
#CenterForCounteringDisinformation
russia continues its hybrid attacks against European states. In particular, Check Point, a cybersecurity company, has reported in its recent research on an operation by the hacker group APT29, targeting European diplomats
👇
April 16, 2025 at 5:24 PM
‼️🇷🇺🇺🇸🍊 "L'unité de renseignement de sécurité d'Amazon a perturbé une campagne de cyberespionnage menée par APT29, un groupe de pirates informatiques lié au Kremlin également connu sous le nom de “Midnight Blizzard” "

united24media.com/latest-news/...
Amazon Blocks Kremlin Cyberattack: Russian Hackers Targeted US Cloud Accounts
APT29, linked to Russia, was disrupting sensitive US entities, including universities and nonprofits, as reported by Ukraine’s CCD on September 1.
united24media.com
September 1, 2025 at 2:18 PM
⚠️ APT29’s watering hole trick uncovered

#Amazon disrupted a watering‑hole campaign by Russia’s #APT29, who hijacked legitimate websites to redirect 10% of visitors into a malicious #Microsoft device‑code auth flow, tricking them into granting unauthorized access.

#ransomNews #APT29 #AuthPhishing
August 31, 2025 at 1:45 PM
Amazon has disrupted a Russian #APT29 watering hole campaign that used compromised websites to target Microsoft’s device code authentication.

Read: hackread.com/amazon-disru...

#CyberSecurity #CyberAttack #Russia #Amazon #Microsoft
Amazon Disrupts Russian APT29 Watering Hole Targeting Microsoft Authentication
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
September 1, 2025 at 11:31 AM