ATT&CKReferencesNCSC et al APT29 2024

NCSC et al APT29 2024

UK National Cyber Security Center et al. (2024, February). SVR cyber actors adapt tactics for initial cloud access. Retrieved March 1, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1078.003
Local Accounts
GroupAPT29

APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence.

T1090.002
External Proxy
GroupAPT29

APT29 uses compromised residential endpoints as proxies for defense evasion and network access.

T1098.005
Device Registration
GroupAPT29

APT29 has enrolled their own devices into compromised cloud tenants, including enrolling a device in MFA to an Azure AD environment following a successful password guessing attack against a dormant account.

T1110.003
Password Spraying
GroupAPT29

APT29 has conducted brute force password spray attacks.

T1528
Steal Application Access Token
GroupAPT29

APT29 uses stolen tokens to access victim accounts, without needing a password.

T1621
Multi-Factor Authentication Request Generation
GroupAPT29

APT29 has used repeated MFA requests to gain access to victim accounts.

T1665
Hide Infrastructure
GroupAPT29

APT29 uses compromised residential endpoints, typically within the same ISP IP address range, as proxies to hide the true source of C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.