Back to Campaigns

APT29 Midnight Blizzard (NOBELIUM): The evolution of stealthy cyber espionage

June 24, 2026 | 3 min

Some threat actors follow trends. Others define them.

APT29, also known as Midnight Blizzard or NOBELIUM, sits firmly in the second category. Over more than a decade, this Russian state-sponsored group has consistently redefined how modern cyber espionage operates—quietly, patiently, and with surgical precision.

From spearphishing campaigns to supply chain compromises and now malware-free attacks leveraging trusted tools, APT29 demonstrates a single truth: attackers evolve faster than traditional defenses.

This campaign explores how APT29 operates today, how its tactics have evolved, and what this means for defenders preparing for real-world incidents.

Understanding APT29 (Midnight Blizzard)

APT29 is a highly sophisticated cyber espionage group attributed to Russia’s Foreign Intelligence Service (SVR). Its mission is clear: collect intelligence from foreign governments, diplomatic entities, and strategic organizations.

Unlike disruptive threat actors, APT29 prioritizes stealth and persistence. It maintains long-term access to target environments, often remaining undetected for extended periods while quietly extracting sensitive data.

The group operates under multiple aliases, including Midnight Blizzard / NOBELIUM (Microsoft), Cozy Bear (CrowdStrike), and The Dukes (security community).

  • Government and diplomatic organizations
  • Defense contractors and think tanks
  • IT service providers and cloud environments

APT29’s campaigns are not opportunistic. They are deliberate, intelligence-driven operations designed to achieve geopolitical objectives.

Key attack definitions

Before diving into the latest campaign, it is important to understand several key techniques APT29 relies on:

Spearphishing (T1566.001)
Targeted phishing emails crafted for specific individuals, often using highly relevant lures.

Supply chain compromise (T1195.002)
Embedding malicious code into trusted software updates to gain access to downstream customers.

Valid account abuse (T1078)
Using legitimate credentials to access systems without triggering traditional alerts.

Living off the land (LOTL)
Leveraging native tools and legitimate system functionality instead of deploying malware.

These techniques share a common theme: blending in. APT29 avoids noisy tactics in favor of methods that look legitimate.

Anatomy of the attack chain

When you examine APT29 campaigns over time, and the pattern becomes clear and focuses on evolving the delivery while preserving the objective.

Phase 1: Traditional intrusion (2016)

The group relied on spearphishing attachments and social media-based command-and-control (C2). It introduced innovative techniques like hiding commands in images hosted on platforms such as Twitter (now X) and GitHub.

What you’ll learn

This campaign is not just about APT29. It is about how modern threats behave and how defenders need to respond.

By the end of this campaign, you will understand:

  • How state-sponsored actors evolve tactics across years, not weeks
  • Why malware-free attacks challenge traditional detection models
  • How identity, cloud, and trusted tools become primary attack surfaces
  • What “living off the land” looks like in real-world operations
  • Why behavioral detection and process monitoring matter more than signatures

Most importantly, you will see how attack chains unfold in practice and where defensive gaps emerge under pressure. You can dive into the introductory theory module on APT29, and then test your newfound knowledge with three Hands-on Labs, all available for free:

  • APT29 Initial Access and Reconnaissance
  • APT29 Persistence and Exfiltration
  • APT29 Detection and Indicators of Compromise
FAQs
What is a cyber range platform?

A cyber range is a simulated digital environment designed for cybersecurity training, experimentation, and research. It replicates real-world networks and attack scenarios, enabling users to practice defending systems in a safe, controlled setting. By leveraging virtual machines and isolated infrastructures, participants can engage in hands-on exercises that mirror real cyber threats without putting production systems or sensitive data at risk.

Unlike traditional, static lab setups, cyber ranges are interactive and responsive. They can introduce authentic attack techniques, simulate realistic network traffic, and adjust scenarios dynamically based on participants’ decisions. This creates an engaging, high-fidelity training experience, essentially a virtual battlefield, where professionals use the same tools and processes they would employ in an operational Security Operations Center (SOC).

What is a cyber range platform?

A cyber range is a simulated digital environment designed for cybersecurity training, experimentation, and research. It replicates real-world networks and attack scenarios, enabling users to practice defending systems in a safe, controlled setting. By leveraging virtual machines and isolated infrastructures, participants can engage in hands-on exercises that mirror real cyber threats without putting production systems or sensitive data at risk.

Unlike traditional, static lab setups, cyber ranges are interactive and responsive. They can introduce authentic attack techniques, simulate realistic network traffic, and adjust scenarios dynamically based on participants’ decisions. This creates an engaging, high-fidelity training experience, essentially a virtual battlefield, where professionals use the same tools and processes they would employ in an operational Security Operations Center (SOC).

What is a cyber range platform?

A cyber range is a simulated digital environment designed for cybersecurity training, experimentation, and research. It replicates real-world networks and attack scenarios, enabling users to practice defending systems in a safe, controlled setting. By leveraging virtual machines and isolated infrastructures, participants can engage in hands-on exercises that mirror real cyber threats without putting production systems or sensitive data at risk.

Unlike traditional, static lab setups, cyber ranges are interactive and responsive. They can introduce authentic attack techniques, simulate realistic network traffic, and adjust scenarios dynamically based on participants’ decisions. This creates an engaging, high-fidelity training experience, essentially a virtual battlefield, where professionals use the same tools and processes they would employ in an operational Security Operations Center (SOC).

Same Job, New Skills Report: What cybersecurity readiness really looks like in 2026