Russian APT29 Group Targets German PoliticiansInfosecurity Magazine·Mar 25, 09:30 UTC · Mar 25, 2024Threat actor57
Russia-linked APT29 reused iOS and Chrome exploits previously developed by NSO Group and IntellexaSecurity Affairs·Aug 30, 05:33 UTC · Aug 30, 2024Threat actor in the wildCVE-2023-41993CVE-2024-5274CVE-2024-4671+1 CVEs60
Russia-linked APT29 targets diplomatic and government organizationsSecurity Affairs·May 2, 05:34 UTC · May 2, 2022Threat actor57
APT29 hit German political parties with bogus invites and malwareHelp Net Security·Mar 25, 00:00 UTC · Mar 25, 2024Malware42
APT29 revamps its techniques to breach cloud environmentsHelp Net Security·Feb 27, 00:00 UTC · Feb 27, 2024Threat actor57
APT29 is targeting Ministries of Foreign Affairs of NATOSecurity Affairs·Aug 17, 23:26 UTC · Aug 17, 2023Threat actor57
APT29 Exploited a Windows Feature to Compromise European Diplomatic Entity NetworkThe Hacker News·Nov 11, 11:51 UTC · Nov 11, 2022Threat actorCVE-2022-3017060
Cybaze ZLab - Yoroi team analyzed malware used in recent APT29 attacksSecurity Affairs·Nov 19, 13:49 UTC · Nov 19, 2018Malware42
Russia-linked APT29 targets European diplomatic entities with GRAPELOADERSecurity Affairs·Apr 21, 08:12 UTC · Apr 21, 2025Malware42
Russia-linked APT29 switched to targeting cloud servicesSecurity Affairs·Jun 30, 12:31 UTC · Jun 30, 2024Threat actor57
Russia-linked APT29 targeted German political parties with WINELOADER backdoorSecurity Affairs·Mar 23, 18:21 UTC · Mar 23, 2024Malware42
Russia-linked APT29 is behind recent attacks targeting NATO and EUSecurity Affairs·Apr 13, 20:19 UTC · Apr 13, 2023Threat actor57
US seizes 2 domains used by APT29 in recent phishing campaignSecurity Affairs·Jun 2, 07:46 UTC · Jun 2, 2021Threat actor57
How the Russian hacking group Cozy Bear, suspected in the SolarWinds breach, plays the long gameCyberScoop·Dec 18, 21:04 UTC · Dec 18, 2020Threat actor57
TeamViewer says Russia’s ‘Cozy Bear’ hackers attacked corporate IT systemThe Record·Jun 28, 18:54 UTC · Jun 28, 2024Threat actor57
APT29 abused Windows Credential Roaming in attacksSecurity Affairs·Nov 10, 10:41 UTC · Nov 10, 2022Threat actorCVE-2022-3017060
Russian APT29 relies on Google Drive, Dropbox to evade detectionSecurity Affairs·Jul 19, 13:41 UTC · Jul 19, 2022Threat actor57
BlueBravo Uses Ambassador Lure to Deploy GraphicalNeutrino MalwareRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Malware42
APT29 Spearphishing Campaign Targets Thousands with RDP FilesInfosecurity Magazine·Oct 30, 10:00 UTC · Oct 30, 2024Threat actor57
Russia-linked group APT29 is targeting Zimbra and JetBrains TeamCity servers on a large scaleSecurity Affairs·Oct 13, 04:38 UTC · Oct 13, 2024Threat actorCVE-2022-27924CVE-2023-4279360
Russia-linked group APT29 likely breached TeamViewerSecurity Affairs·Jun 30, 12:44 UTC · Jun 30, 2024Data breach57
Russian APT29 Hackers Use Online Storage Services, DropBox and Google DrivePalo Alto Unit 42·Jun 5, 20:16 UTC · Jun 5, 2024Threat actor57
APT29 abuses EU information exchange systems in recent attacksSecurity Affairs·Mar 15, 23:28 UTC · Mar 15, 2023Threat actor57
Running for Office: Russian APT Toolkits RevealedRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Ransomware in the wildCVE-2014-3897CVE-2013-3897260
Google says Russian group targeted Mongolian government with exploits used by NSO GroupThe Record·Aug 29, 15:07 UTC · Aug 29, 2024VulnerabilityCVE-2023-41993CVE-2024-5274CVE-2024-4671+1 CVEs47
Microsoft Warns of Widening APT29 Espionage Attacks Targeting Global OrgsThe Hacker News·Jan 27, 06:01 UTC · Jan 27, 2024Threat actor57
Additional Entities Targeted by DarkSide Affiliate, TAG-21; Links to WellMess and Sliver InfrastructureRecorded Future·Jul 15, 00:00 UTC · Jul 15, 2025Ransomware57
TeamViewer Detects Security Breach in Corporate IT EnvironmentThe Hacker News·Jul 7, 16:52 UTC · Jul 7, 2024Threat actor in the wild60
Five Eyes Agencies Expose APT29's Evolving Cloud Attack TacticsThe Hacker News·Feb 28, 03:29 UTC · Feb 28, 2024Threat actor57
CISA Issues Alert on APT29’s Cloud Infiltration TacticsInfosecurity Magazine·Feb 26, 17:15 UTC · Feb 26, 2024Threat actor57
CISA, FBI, NSA reveal five enterprise bugs exploited by Russia's APT29 groupThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Threat actorCVE-2018-13379CVE-2019-9670CVE-2019-11510+2 CVEs60
Russian-Related Threats to the 2020 US Presidential ElectionRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Ransomware57
Russian Hackers Use 'WINELOADER' Malware to Target German Political PartiesThe Hacker News·Mar 23, 06:03 UTC · Mar 23, 2024Malware42
Cyber-espionage operation on embassies linked to Russia’s Cozy Bear hackersThe Record·Nov 14, 16:45 UTC · Nov 14, 2023Threat actorCVE-2023-3883160
Russian Hackers Targeting Diplomatic Entities in Europe, Americas, and AsiaThe Hacker News·May 11, 02:46 UTC · May 11, 2022Data breach57
Experts Uncover Several C&C Servers Linked to WellMess MalwareThe Hacker News·Jul 30, 10:00 UTC · Jul 30, 2021Malware42
Microsoft Uncovers New Post-Compromise Malware Used by Nobelium HackersThe Hacker News·Aug 30, 03:22 UTC · Aug 30, 2022Malware42
Researchers Find Additional Infrastructure Used By SolarWinds HackersThe Hacker News·Apr 22, 16:39 UTC · Apr 22, 2021Malware42
Exclusive - Hunting Cozy Bear, new campaign, old habitsSecurity Affairs·Nov 23, 10:38 UTC · Nov 23, 2018Threat actor57