APT · Russia
Sophisticated APT known for SolarWinds supply chain intrusion and cloud identity targeting across Western governments.
Aliases: Cozy Bear, The Dukes, NOBELIUM
Motivation: Long-term espionage and supply chain compromise
Reconnaissance
Field telemetry from Seoul correlates with Microsoft Patches Actively Exploited Edge Zero-Day.
Initial Access
Field telemetry from London correlates with APT29 Targets Cloud Identity Providers in NATO States.
Resolution
Field telemetry from Stockholm correlates with Play Ransomware Exploits Fortinet Zero-Day in Government Sector.
Initial Access
Field telemetry from Seoul correlates with Microsoft Patches Actively Exploited Edge Zero-Day.
Privilege Escalation
Field telemetry from London correlates with APT29 Targets Cloud Identity Providers in NATO States.
Reconnaissance
Field telemetry from Stockholm correlates with Play Ransomware Exploits Fortinet Zero-Day in Government Sector.
Lateral Movement
Field telemetry from London correlates with APT29 Targets Cloud Identity Providers in NATO States.
Initial Access
Field telemetry from Stockholm correlates with Play Ransomware Exploits Fortinet Zero-Day in Government Sector.
Privilege Escalation
Field telemetry from Seoul correlates with Microsoft Patches Actively Exploited Edge Zero-Day.