Darkhalo

Threat Actor updated 4 months ago (2024-05-04T16:37:55.605Z)
Download STIX
Preview STIX
DarkHalo, also known as APT29, Cozy Bear, and tracked by Microsoft as Midnight Blizzard (previously NOBELIUM), is a sophisticated threat actor suspected of executing actions with malicious intent. These actions typically involve cyber attacks and are often attributed to either individual hackers, private companies, or government entities. According to a report by the Redmond-based tech giant, Microsoft, DarkHalo has been involved in targeted social engineering attacks over Microsoft Teams. In December 2020, an analysis of the DNS-based protocol of a malicious implant linked to DarkHalo revealed that it leaked the identities of selected victims for further exploitation. This finding was significant because it provided insight into the methods and strategies employed by this threat actor, which could potentially aid in the development of more effective defensive measures against future attacks. FireEye, a prominent cybersecurity firm, discovered the first traces of a campaign believed to have been orchestrated by DarkHalo (also referred to as Nobelium). The discovery suggested that the threat actor had been operating undetected for over a year, indicating a high level of sophistication and stealth in their operations. This long-term, covert activity underscores the persistent and evolving nature of the threats posed by actors like DarkHalo, emphasizing the need for continuous vigilance and advanced security measures in the digital landscape.
Description last updated: 2023-10-11T01:00:01.471Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
NOBELIUM
2
Nobelium, a threat actor linked to Russia, has been identified as a significant cybersecurity concern due to its targeted attacks on diplomatic entities in France and other European Union (EU) governments. The group, known by various names including APT29, SVR Group, Cozy Bear, Midnight Blizzard, an
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Darkhalo Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
Tomiris backdoor and its connection to Sunshuttle and Kazuar
CERT-EU
a year ago
Russian APT Group Seen Targeting Victims Over Microsoft Teams