#APT29

SoyArmeniosoyarmernio
2025-05-03

Azerbaiyán acusa a Rusia de un ciberataque a medios locales a través del grupo APT29. La tensión crece antes de las visitas de Netanyahu y Erdogan a Bakú, en un contexto de distanciamiento geopolítico. soyarmenio.com/noticias-intern

2025-05-03

Azerbaijani blames #Russia for February #cyberattack

An investigation found the Feb 20th cyberattack against #Azerbaijan was carried out by infamous APT29 group, aka Cozy Bear, widely believed linked to #Russia’s Foreign Intelligence Service

Activities of #APT29, which is engaged in #cyber e#spionage, are mainly directed against govt agencies, foreign diplomatic missions, political, defense, energy, media and other critical areas

kyivindependent.com/azerbaijan

#RussianAggression #HybridWar

2025-04-22

Renewed APT29 Phishing Campaign Against European Diplomats

research.checkpoint.com/2025/a

#apt29 #phishing #campaign

"Infrastructure risks have also been prominent, w/vulnerabilities in ASUS routers & critical ICS devices from Schneider Electric & Yokogawa exposing sectors like #energy & manufacturing to..." digitalfrontierpartners.com.au/news/latest-... RU #APT29 Android #NFC China #UNC5221 #SNOWLIGHT #TONESHELL

Latest Sophisticated Attacks a...

2025-04-19

Russian hacker group Cozy Bear (aka #MidnightBlizzard, APT29) is back, using wine-tasting invites to phish EU diplomats. The bait? A new wave of WineLoader malware. 🍷🎣

Read: hackread.com/cozy-bear-wine-lu

#CyberSecurity #APT29 #WineLoader #Russia #EU

Just Another Blue TeamerLeeArchinal@ioc.exchange
2025-04-17

Good day everyone!

Check Point Software researchers produced another great article that involves #APT29 and #phishing and a little bit of masquerading. This phishing campaign targeted European diplomatic entities that distributes fake invitations to diplomatic events and appears to be a continuation of a previous campaign run by the same actors. These phishing emails utilized a backdoor known as #Wineloader and also employs a new loader #Grapeloader. There is a lot to unpack here and I hope you enjoy!

Renewed APT29 Phishing Campaign Against European Diplomats
research.checkpoint.com/2025/a

Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

Brian Greenberg :verified:brian_greenberg@infosec.exchange
2025-04-17

🍷 Cozy Bear (APT29) is back — and this time, they’re targeting EU diplomats with fake wine-tasting invitations.

The attack chain:
📧 Emails impersonating foreign ministries
📎 Attachments loaded with GRAPELOADER
🎯 Embassies, diplomats, and government agencies in the crosshairs
🧠 Classic social engineering — elegant, persistent, and dangerous

Threat actors don’t need zero-days when polished social engineering still works.

#CyberSecurity #APT29 #ThreatIntel #Phishing #DiplomaticSecurity
helpnetsecurity.com/2025/04/16

Opalsec :verified:Opalsec@infosec.exchange
2025-03-30

Our latest blog post is live, check it out!

🗞️ opalsec.io/daily-news-update-s

* 👾 Obscure Programming Languages in Malware: Malware authors are getting creative, using less common languages like Rust, Nim, Phix, Lisp and Haskell to evade detection - and it works.
* 💔 $8.2 Million Seized in Crypto Romance Baiting: The DOJ just seized millions in USDT from "romance baiting" scams (aka pig butchering), with links to human trafficking in Cambodia and Myanmar. This is a stark reminder of the human element in cybercrime.

Don't forget, you can subscribe to our newsletter here to get the updates straight to your inbox!

📨opalsec.io/daily-news-update-s

#cybersecurity #malware #ransomware #cryptoscams #threatintel #infosec #rustlang #phishing #APT29 #pigbutchering #usdt #doj #fbi #cybercrime #securityresearch #zerotrust #threatdetection #reversengineering

2025-02-14
2024-12-18

Christmas nears, the "Wild Hunt" too And with it the Koshchei rides anew: thehackernews.com/2024/12/apt2... as a monster in the middle he hides and spies as a config among configs in disguise leave your laptop let your emails lay have no rush on Christmas day. #cybersec #apt29 #christmas #hacker

RoundSparrow 🐦RoundSparrow
2024-12-01

16 July 2020

APT29 (also known as ‘the Dukes’ or ‘Cozy Bear’) is a cyber espionage group, almost certainly part of the Russian intelligence services. The United States’ National Security Agency (NSA) agrees with this attribution and the details provided in this report.

ncsc.gov.uk/news/advisory-apt2

2024-11-18

Nowy sposób na kradzież danych z systemów Windows – malware via RDP, kampania rosyjskiej grupy APT29

Rosyjska grupa APT „Midnight Blizzard” wykorzystuje pliki .rdp w kampanii malware, która umożliwia kradzież danych z dysków użytkowników oraz dystrybucję złośliwego oprogramowania w sieci ofiary. Atak polega na oszukaniu użytkownika, aby otworzył spreparowany plik .rdp, co skutkuje kradzieżą danych i potencjalnym zainfekowaniem innych urządzeń. Nasi pentesterzy natrafili na ślady tej...

#Teksty #WBiegu #Apt29 #Malware #Microsoft #Rdp #Stealer

sekurak.pl/nowy-sposob-na-krad

2024-10-30
New campaign by #APT29 | https://therecord.media/russia-midnight-blizzard-hackers-target-government-sector
2024-10-28

#AWS#ロシア#APT29 が使う #ドメイン#差し押さえ | Codebook|Security News
... Amazon Web Services (AWS) は24日、ロシアの #脅威アクター APT29が #フィッシング攻撃 ... 標的にされなかったとのこと …
codebook.machinarecord.com/thr

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst