Cozy Bear

Actor Type Nation State
Attributed to Nation Russia
Directly Linked Intrusion Sets APT29 , Midnight Blizzard , The Dukes , NOBELIUM
Associated Threat Actor SVR - Russian Foreign Intelligence Service

COZY BEAR is a Russian adversary tracked by CrowdStrike and linked to the SVR. COZY BEAR is one of the adversaries identified during the intrusion against the US Democratic National Committee in 2016.

Cyber Threat Graph Context

Explore how this Intrusion Set relates to the wider threat graph

Cozy Bear Threat Reports

Report

Midnight Blizzard: Guidance for responders on nation-state attack

Following a compromise of Microsoft corporate systems by Midnight Blizzard which was detected on 12th January 2024, this blog post outlines ...

Report

SVR cyber actors adapt tactics for initial cloud access

This advisory from the UK's National Cyber Security Centre (NCSC) outlines tactics, techniques and procedures (TTPs) used by the cyber actors ...

References

MITRE ATT&CK Techniques

MITRE ATT&CK techniques observed in use by this intrusion set.