CozyDuke

Threat Actor updated 4 months ago (2024-05-04T19:37:25.590Z)
Download STIX
Preview STIX
CozyDuke, also known as Cozy Bear or APT29, is a prominent threat actor recognized for its malicious activities against Western government organizations and a variety of industries. The group has successfully infiltrated the unclassified networks of several high-profile entities, including the White House, the State Department, and the US Joint Chiefs of Staff. Their targets span across multiple sectors, such as Defense, Energy, Extractive, Financial, Insurance, Legal, Manufacturing Media, Think Tanks, Pharmaceutical, Research and Technology, and Universities. The group's activities were notably observed during the milestone DNC hack event where both Sofacy and CozyDuke were present, with Turla being absent. Despite this, Turla was found to be quietly active around the globe on other projects, hinting at the diverse motivations and ambitions of these threat actors. CozyDuke's operations are not limited to direct attacks; they have also been linked to the creation of sophisticated backdoors, enabling further exploitation of compromised systems. CozyDuke is responsible for several significant attacks, such as those associated with MiniDuke and CosmicDuke. These attacks often involve advanced persistent threats (APTs), which are prolonged and targeted cyberattacks where the attacker gains access to a network and remains undetected for an extended period. The group is known by various other names, including IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, StellarParticle, NOBELIUM, UNC2452, YTTRIUM, The Dukes, and Cozy Bear, reflecting the complex and multifaceted nature of their operations.
Description last updated: 2023-10-10T20:31:32.920Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CozyDuke Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
Our Work with the DNC: Setting the record straight
MITRE
2 years ago
Shedding Skin - Turla’s Fresh Faces | Securelist
MITRE
2 years ago
Minidionis – one more APT with a usage of cloud drives
Trend Micro
2 years ago
Invitation to a Secret Event: Uncovering Earth Yako’s Campaigns