Five Eyes Agencies Expose APT29's Evolving Cloud Attack Tactics
ID: d33f7513-5837-55d8-ae33-7265fcbb92d5
STIX ID: report--d33f7513-5837-55d8-ae33-7265fcbb92d5
Feed Name: The Hacker News
Threat Score
**APT29 (Cozy Bear)** — Five Eyes agencies warn that the SVR‑aligned threat actor has shifted to cloud‑centric intrusion methods, using brute‑force and password‑spraying against service/dormant accounts, token theft, credential reuse and prompt‑bombing to bypass MFA, and residential proxies to mask origin; the actor continues to target organizations (including Microsoft and HPE) and can deploy advanced post‑compromise tools such as MagicWeb.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
