DarkHalo, also known as APT29, Cozy Bear, and tracked by Microsoft as Midnight Blizzard (previously NOBELIUM), is a sophisticated threat actor suspected of executing actions with malicious intent. These actions typically involve cyber attacks and are often attributed to either individual hackers, private companies, or government entities. According to a report by the Redmond-based tech giant, Microsoft, DarkHalo has been involved in targeted social engineering attacks over Microsoft Teams.
In December 2020, an analysis of the DNS-based protocol of a malicious implant linked to DarkHalo revealed that it leaked the identities of selected victims for further exploitation. This finding was significant because it provided insight into the methods and strategies employed by this threat actor, which could potentially aid in the development of more effective defensive measures against future attacks.
FireEye, a prominent cybersecurity firm, discovered the first traces of a campaign believed to have been orchestrated by DarkHalo (also referred to as Nobelium). The discovery suggested that the threat actor had been operating undetected for over a year, indicating a high level of sophistication and stealth in their operations. This long-term, covert activity underscores the persistent and evolving nature of the threats posed by actors like DarkHalo, emphasizing the need for continuous vigilance and advanced security measures in the digital landscape.
Description last updated: 2023-10-11T01:00:01.471Z