Advanced Persistent Threat 29 – Russian State-Sponsored
Executive Summary
APT29 (also known as Cozy Bear, The Dukes, The Fancy Bears) is a Russian state-sponsored advanced persistent threat group primarily focused on espionage, intellectual property theft, and political operations. This report covers their operations as of 2026, including their recent campaigns, tools, TTPs, and target sectors.


Basic Information
- Name: APT29 (Cozy Bear)
- Aliases: APT29, The Dukes, The Fancy Bears, Cozy Bear, Dukes
- MITRE ATT&CK Group ID: G0016
- Country of Origin: Russia
- Threat Level: CRITICAL
- Primary Motivation: State-sponsored espionage, political influence, intellectual property theft

Recent Operations (2025-2026)
Healthcare Sector (2025-2026):
- Targeting U.S. healthcare research institutes
- Compromising hospital IT systems
- Stealing patient data and research records
- Using Cobalt Strike for post-exploitation
Technology Sector (2025-2026):
- Semiconductor company targeting
- AI/ML research institution operations
- Biotechnology sector compromise
- Pharmaceutical company espionage
Government Sector (2025-2026):
- U.S. government political targeting
- Think tank operations
- Congressional office compromise
- Diplomatic mission targeting
Primary Tools:
- Cobalt Strike (primary post-exploitation)
- Custom malware (Cozy Bear framework)
- Zero-day exploitation
- Spearphishing campaigns
- Credential dumping (Mimikatz, BloodHound)

TTPs (MITRE ATT&CK Mapping)
Initial Access:
- Phishing (Spearphishing Link, Spearphishing Attachment)
- Supply chain compromise
- Exploit publicly available vulnerabilities
Execution:
- Browser Execution
- PowerShell
- Command and Scripting Interpreter
Persistence:
- Boot/Logon Autostart
- Accessibility Features
- Lateral Tool Transfer
Privilege Escalation:
- Exploitation for Privilege Escalation
- Abuse Elevation Control Mechanism
Defense Evasion:
- Indicator Removal
- File and Directory Permissions Modification
- Obfuscated Files or Information
Credential Access:
- Credential Dumping (LSASS Memory)
- Remote Service Discovery
Discovery:
- Active Directory Enumeration
- Network Service Discovery
Lateral Movement:
- Remote Services (RDP, SMB)
- Remote Services (SMB)
Collection:
- Data from Local System
- Data from Network
Exfiltration:
- Exfiltration Over C2 Channel
- Exfiltration Over Alternative Protocol

Known Campaigns (2025-2026)
Operation 1 (2025):
- Target: U.S. healthcare research institutes
- Impact: Patient data exposure, research data theft
- Tools: Cobalt Strike, custom malware
Operation 2 (2025):
- Target: Technology sector (semiconductor, AI companies)
- Impact: IP theft, trade secret compromise
- Tools: Cobalt Strike, Mimikatz
Operation 3 (2026):
- Target: Government and political entities
- Impact: Political influence, information warfare
- Tools: Cobalt Strike, zero-day exploits

Threat Assessment
Threat Level: CRITICAL
Primary Targets:
- Government and military
- Healthcare sector
- Technology and research
- Political entities
Capabilities:
- Advanced persistent threat
- Zero-day exploitation
- Multi-vector attacks
- Long-term persistence
- Information warfare

Sources
- MITRE ATT&CK G0016
- CrowdStrike Threat Intelligence
- Mandiant Reports
- CISA Advisories
- FBI Reports
- HHS.gov
- Brandefense
- FortiGuard Labs

Report Generated: 2026-06-10
Intelligence Freshness: Current (as of June 2026)
Classification: Unclassified
