home.social

#apt29 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #apt29, aggregated by home.social.

  1. 📢 ConsentFix v3 : un nouveau toolkit criminel OAuth diffusé sur le forum XSS
    📝 ## 🔍 Contexte

    Publié le 23 avril 2026 par Push Security, cet article analyse **ConsentFix v3**, un nouveau toolkit criminel diffusé sur le forum **XSS** (s...
    📖 cyberveille : cyberveille.ch/posts/2026-04-2
    🌐 source : pushsecurity.com/blog/consentf
    #APT29 #ConsentFix #Cyberveille

  2. "Patch Your Network" - A powerful EDM track about defending against sophisticated adversaries! Featuring AENDZI's incredible vocals & a danceable groove that makes security awareness unforgettable. Remember: APT29 is watching!
    Watch here: youtube.com/watch?v=VL57hVgsq9g
    #cybersecurity #infosec #APT29 #music #EDM #security

  3. Operational summary:
    Threat actor: UAC-0050
    Alias: DaVinci Group / Mercenary Akula (per BlueVoyant)
    Tooling: RMS (Remote Manipulator System)
    Delivery: Spear-phishing, spoofed judicial domain, layered archives
    TTP alignment consistent with reporting from CERT-UA.

    Strategic overlay:
    Russia-nexus actors, including APT29, continue high-confidence trust exploitation campaigns, as outlined by CrowdStrike.

    Detection priorities:
    - Monitor MSI execution anomalies
    - Flag double-extension binaries
    - Inspect outbound RMS traffic
    - Harden executive email authentication
    Follow for tactical intelligence briefings.
    Comment with detection engineering recommendations.

    #Infosec #ThreatIntel #UAC0050 #APT29 #RMS #SpearPhishing #DetectionEngineering #CyberEspionage #SOC #BlueTeam #SecurityOperations

  4. "Patch Your Network" - A powerful EDM track about defending against sophisticated adversaries! Featuring AENDZI's incredible vocals & a danceable groove that makes security awareness unforgettable. Remember: APT29 is watching!
    Watch here: youtube.com/watch?v=VL57hVgsq9g
    #cybersecurity #infosec #APT29 #music #EDM #security

  5. "Patch Your Network" - A powerful EDM track about defending against sophisticated adversaries! Featuring AENDZI's incredible vocals & a danceable groove that makes security awareness unforgettable. Remember: APT29 is watching!
    Watch here: youtube.com/watch?v=VL57hVgsq9g
    #cybersecurity #infosec #APT29 #music #EDM #security

  6. They're called "cozy" because they're in no hurry: once they enter a system, they stay there for months undetected, gathering intel from sensitive targets. This is how Russia spies on the West.

    #APT29 #cozyBear #espionage #Russia #cyberwarfare

    negativepid.blog/cyber-warfare

  7. "Patch Your Network" - A powerful EDM track about defending against sophisticated adversaries! Featuring AENDZI's incredible vocals & a danceable groove that makes security awareness unforgettable. Remember: APT29 is watching!
    Watch here: youtube.com/watch?v=VL57hVgsq9
    #cybersecurity #infosec #APT29 #music #EDM #security

  8. "Patch Your Network" - A powerful EDM track about defending against sophisticated adversaries! Featuring AENDZI's incredible vocals & a danceable groove that makes security awareness unforgettable. Remember: APT29 is watching!
    Watch here: youtube.com/watch?v=VL57hVgsq9
    #cybersecurity #infosec #APT29 #music #EDM #security

  9. Russian hacker group Cozy Bear (aka #MidnightBlizzard, APT29) is back, using wine-tasting invites to phish EU diplomats. The bait? A new wave of WineLoader malware. 🍷🎣

    Read: hackread.com/cozy-bear-wine-lu

    #CyberSecurity #APT29 #WineLoader #Russia #EU

  10. Russian hacker group Cozy Bear (aka , APT29) is back, using wine-tasting invites to phish EU diplomats. The bait? A new wave of WineLoader malware. 🍷🎣

    Read: hackread.com/cozy-bear-wine-lu

  11. Russian hacker group Cozy Bear (aka #MidnightBlizzard, APT29) is back, using wine-tasting invites to phish EU diplomats. The bait? A new wave of WineLoader malware. 🍷🎣

    Read: hackread.com/cozy-bear-wine-lu

    #CyberSecurity #APT29 #WineLoader #Russia #EU

  12. Russian hacker group Cozy Bear (aka #MidnightBlizzard, APT29) is back, using wine-tasting invites to phish EU diplomats. The bait? A new wave of WineLoader malware. 🍷🎣

    Read: hackread.com/cozy-bear-wine-lu

    #CyberSecurity #APT29 #WineLoader #Russia #EU

  13. Russian hacker group Cozy Bear (aka #MidnightBlizzard, APT29) is back, using wine-tasting invites to phish EU diplomats. The bait? A new wave of WineLoader malware. 🍷🎣

    Read: hackread.com/cozy-bear-wine-lu

    #CyberSecurity #APT29 #WineLoader #Russia #EU

  14. Good day everyone!

    Check Point Software researchers produced another great article that involves #APT29 and #phishing and a little bit of masquerading. This phishing campaign targeted European diplomatic entities that distributes fake invitations to diplomatic events and appears to be a continuation of a previous campaign run by the same actors. These phishing emails utilized a backdoor known as #Wineloader and also employs a new loader #Grapeloader. There is a lot to unpack here and I hope you enjoy!

    Renewed APT29 Phishing Campaign Against European Diplomats
    research.checkpoint.com/2025/a

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  15. Good day everyone!

    Check Point Software researchers produced another great article that involves #APT29 and #phishing and a little bit of masquerading. This phishing campaign targeted European diplomatic entities that distributes fake invitations to diplomatic events and appears to be a continuation of a previous campaign run by the same actors. These phishing emails utilized a backdoor known as #Wineloader and also employs a new loader #Grapeloader. There is a lot to unpack here and I hope you enjoy!

    Renewed APT29 Phishing Campaign Against European Diplomats
    research.checkpoint.com/2025/a

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  16. Good day everyone!

    Check Point Software researchers produced another great article that involves #APT29 and #phishing and a little bit of masquerading. This phishing campaign targeted European diplomatic entities that distributes fake invitations to diplomatic events and appears to be a continuation of a previous campaign run by the same actors. These phishing emails utilized a backdoor known as #Wineloader and also employs a new loader #Grapeloader. There is a lot to unpack here and I hope you enjoy!

    Renewed APT29 Phishing Campaign Against European Diplomats
    research.checkpoint.com/2025/a

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  17. Good day everyone!

    Check Point Software researchers produced another great article that involves #APT29 and #phishing and a little bit of masquerading. This phishing campaign targeted European diplomatic entities that distributes fake invitations to diplomatic events and appears to be a continuation of a previous campaign run by the same actors. These phishing emails utilized a backdoor known as #Wineloader and also employs a new loader #Grapeloader. There is a lot to unpack here and I hope you enjoy!

    Renewed APT29 Phishing Campaign Against European Diplomats
    research.checkpoint.com/2025/a

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  18. Good day everyone!

    Check Point Software researchers produced another great article that involves #APT29 and #phishing and a little bit of masquerading. This phishing campaign targeted European diplomatic entities that distributes fake invitations to diplomatic events and appears to be a continuation of a previous campaign run by the same actors. These phishing emails utilized a backdoor known as #Wineloader and also employs a new loader #Grapeloader. There is a lot to unpack here and I hope you enjoy!

    Renewed APT29 Phishing Campaign Against European Diplomats
    research.checkpoint.com/2025/a

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  19. Our latest blog post is live, check it out!

    🗞️ opalsec.io/daily-news-update-s

    * 👾 Obscure Programming Languages in Malware: Malware authors are getting creative, using less common languages like Rust, Nim, Phix, Lisp and Haskell to evade detection - and it works.
    * 💔 $8.2 Million Seized in Crypto Romance Baiting: The DOJ just seized millions in USDT from "romance baiting" scams (aka pig butchering), with links to human trafficking in Cambodia and Myanmar. This is a stark reminder of the human element in cybercrime.

    Don't forget, you can subscribe to our newsletter here to get the updates straight to your inbox!

    📨opalsec.io/daily-news-update-s

    #cybersecurity #malware #ransomware #cryptoscams #threatintel #infosec #rustlang #phishing #APT29 #pigbutchering #usdt #doj #fbi #cybercrime #securityresearch #zerotrust #threatdetection #reversengineering

  20. Happy Friday everyone!

    A Joint Advisory from the National Security Agency, Federal Bureau of Investigation (FBI), Cyber National Mission Force, and the National Cyber Security Centre provides updates on the Russian Federation's Foreign Intelligence Service, or #SVR.

    According to the advisory, #APT29 (a.k.a Midnight Blizzard, Cozy Bear, and the Dukes) has targeted the defense, technology, and finance sectors to collect foreign intelligence and enable future cyber operations. They aim to exploit software vulnerabilities for initial access and escalate privileges. They also utilize spearphishing campaigns, password spraying, abuse of supply chain and trusted relationships. They also utilize custom malware and living-off-the-land (LOLBINs) techniques for multiple techniques.

    The report includes a list of #CVEs that APT29 has been observed exploiting and attach the vendor and product that are effected with details that describe the vulnerability along with a section of mitigations that your organization can take to increase your security posture.

    If you are looking for behaviors that are attributed to APT29, look no further than the MITRE ATT&CK Matrix! This resource has collected historic #TTPs and behaviors and referenced them as well. So while you are working on hardening your environment you can also hunt for their activity as well! Enjoy and Happy Hunting!

    Article Source:
    Update on SVR Cyber Operations and Vulnerability Exploitation
    ic3.gov/Media/News/2024/241010

    Mitre source:
    attack.mitre.org/groups/G0016/

    Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #huntoftheday #gethunting Cyborg Security, Now Part of Intel 471