logo

Five Eyes Agencies Expose APT29's Evolving Cloud Attack Tactics

ID: d33f7513-5837-55d8-ae33-7265fcbb92d5

STIX ID: report--d33f7513-5837-55d8-ae33-7265fcbb92d5

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-02-27

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**APT29 (Cozy Bear)** — Five Eyes agencies warn that the SVR‑aligned threat actor has shifted to cloud‑centric intrusion methods, using brute‑force and password‑spraying against service/dormant accounts, token theft, credential reuse and prompt‑bombing to bypass MFA, and residential proxies to mask origin; the actor continues to target organizations (including Microsoft and HPE) and can deploy advanced post‑compromise tools such as MagicWeb.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.