Russian APT29 Group Targets German PoliticiansInfosecurity Magazine·Mar 25, 09:30 UTC · Mar 25, 2024Threat actor57
Amazon Stops Russian APT29 Watering Hole AttackInfosecurity Magazine·Sep 1, 11:00 UTC · Sep 1, 2025Threat actor60
Russia-linked APT29 reused iOS and Chrome exploits previously developed by NSO Group and IntellexaSecurity Affairs·Aug 30, 05:33 UTC · Aug 30, 2024Threat actor in the wildCVE-2023-41993CVE-2024-5274CVE-2024-4671+1 CVEs60
Russia-linked Cozy Bear uses evasive TTPs to target Microsoft 365Security Affairs·Aug 19, 23:20 UTC · Aug 19, 2022Threat actor160
Russia-linked APT29 targets diplomatic and government organizationsSecurity Affairs·May 2, 05:34 UTC · May 2, 2022Threat actor57
UK NCSC blames APT29 for attacks on COVIDSecurity Affairs·Jul 16, 14:46 UTC · Jul 16, 2020Threat actor60
APT29 group used domain fronting to evade detection long before these techniques were widely knownSecurity Affairs·Mar 28, 05:30 UTC · Mar 28, 2017Threat actor45
Amazon shuts down watering hole attack attributed to Russia’s APT29 hacking groupThe Record·Sep 3, 00:03 UTC · Sep 3, 2025Threat actor45
Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code AuthenticationThe Hacker News·Aug 30, 04:26 UTC · Aug 30, 2025Threat actor45
APT29 hit German political parties with bogus invites and malwareHelp Net Security·Mar 25, 00:00 UTC · Mar 25, 2024Malware42
APT29 revamps its techniques to breach cloud environmentsHelp Net Security·Feb 27, 00:00 UTC · Feb 27, 2024Threat actor57
APT29 is targeting Ministries of Foreign Affairs of NATOSecurity Affairs·Aug 17, 23:26 UTC · Aug 17, 2023Threat actor57
Russian APT29 conducts phishing attacks through Microsoft TeamsSecurity Affairs·Aug 3, 07:21 UTC · Aug 3, 2023Threat actor45
UK and US share more vulnerabilities exploited by Russia's APT29 hackersThe Record·Dec 9, 00:00 UTC · Dec 9, 2022Vulnerability in the wildCVE-2018-13379CVE-2019-1653CVE-2019-2725+9 CVEs60
APT29 Exploited a Windows Feature to Compromise European Diplomatic Entity NetworkThe Hacker News·Nov 11, 11:51 UTC · Nov 11, 2022Threat actorCVE-2022-3017060
Cybaze ZLab - Yoroi team analyzed malware used in recent APT29 attacksSecurity Affairs·Nov 19, 13:49 UTC · Nov 19, 2018Malware42
Amazon blocks APT29 campaign targeting Microsoft device code authenticationSecurity Affairs·Aug 31, 05:46 UTC · Aug 31, 2025Threat actor145
Russia-linked APT29 targets European diplomatic entities with GRAPELOADERSecurity Affairs·Apr 21, 08:12 UTC · Apr 21, 2025Malware42
Russia-linked APT29 switched to targeting cloud servicesSecurity Affairs·Jun 30, 12:31 UTC · Jun 30, 2024Threat actor57
Russia-linked APT29 targeted German political parties with WINELOADER backdoorSecurity Affairs·Mar 23, 18:21 UTC · Mar 23, 2024Malware42
Russia-linked APT29 spotted targeting JetBrains TeamCity serversSecurity Affairs·Dec 14, 15:12 UTC · Dec 14, 2023Threat actorCVE-2023-4279360
APT29 group exploited WinRAR 0day in attacks against embassiesSecurity Affairs·Nov 20, 13:44 UTC · Nov 20, 2023Threat actorCVE-2023-3883160
Russia-linked APT29 is behind recent attacks targeting NATO and EUSecurity Affairs·Apr 13, 20:19 UTC · Apr 13, 2023Threat actor57
US seizes 2 domains used by APT29 in recent phishing campaignSecurity Affairs·Jun 2, 07:46 UTC · Jun 2, 2021Threat actor57
How the Russian hacking group Cozy Bear, suspected in the SolarWinds breach, plays the long gameCyberScoop·Dec 18, 21:04 UTC · Dec 18, 2020Threat actor57
Commercial spyware vendor exploits used by KremlinArs Technica · Security·Aug 29, 21:05 UTC · Aug 29, 2024MalwareCVE-2023-41993CVE-2024-5274CVE-2024-4671+1 CVEs60
TeamViewer says Russia’s ‘Cozy Bear’ hackers attacked corporate IT systemThe Record·Jun 28, 18:54 UTC · Jun 28, 2024Threat actor57
APT29 abused Windows Credential Roaming in attacksSecurity Affairs·Nov 10, 10:41 UTC · Nov 10, 2022Threat actorCVE-2022-3017060
Russian APT29 relies on Google Drive, Dropbox to evade detectionSecurity Affairs·Jul 19, 13:41 UTC · Jul 19, 2022Threat actor57
Russia-linked APT29 group changes TTPs following April advisoriesSecurity Affairs·May 7, 21:03 UTC · May 7, 2021Threat actorCVE-2021-26855CVE-2018-13379CVE-2019-1653+9 CVEs50
Suspected APT29 hackers behind attacks on US gov agenciesSecurity Affairs·Nov 18, 09:35 UTC · Nov 18, 2018Threat actor45
BlueBravo Uses Ambassador Lure to Deploy GraphicalNeutrino MalwareRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Malware42
APT29 group used red team tools in rogue RDP attacksSecurity Affairs·Dec 18, 22:24 UTC · Dec 18, 2024AI safety & security30
APT29 Spearphishing Campaign Targets Thousands with RDP FilesInfosecurity Magazine·Oct 30, 10:00 UTC · Oct 30, 2024Threat actor57
CISA Warns of Threat Actors Exploiting F5 BIGThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2024Threat actorCVE-2022-27924CVE-2023-4279360
Russia-linked group APT29 is targeting Zimbra and JetBrains TeamCity servers on a large scaleSecurity Affairs·Oct 13, 04:38 UTC · Oct 13, 2024Threat actorCVE-2022-27924CVE-2023-4279360
Russia-linked group APT29 likely breached TeamViewerSecurity Affairs·Jun 30, 12:44 UTC · Jun 30, 2024Data breach57
Russian APT29 Hackers Use Online Storage Services, DropBox and Google DrivePalo Alto Unit 42·Jun 5, 20:16 UTC · Jun 5, 2024Threat actor57
APT29 abuses EU information exchange systems in recent attacksSecurity Affairs·Mar 15, 23:28 UTC · Mar 15, 2023Threat actor57