If you think LockBit or BlackCat are your biggest problems, you’re playing checkers while the SVR is playing 4D chess.
We just finished a deep dive into APT29 (aka Midnight Blizzard / Nobelium), and the shift in their tradecraft over the last 18 months is terrifying. They aren't smashing windows anymore; they are forging the keys to the front door.
We often focus on the noisy "smash-and-grab" ransomware gangs, but Cozy Bear represents the "silent killer" of modern networks. They don't want your moneym they want your geopolitical strategy, your R&D, and your emails.
Here is the TL;DR on their modern doctrine:
Identity is the New Perimeter:
They stopped trying to brute force firewalls. Now, they target the Identity Provider (IdP). If they get your ADFS signing keys (Golden SAML) or compromise a legacy tenant (like they did to Microsoft), they can mint their own authentication tokens. They bypass MFA not by hacking it, but by becoming the system that checks it.
The "Microsoft Tax"
Their breach of Microsoft wasn't sophisticated zero-day magic. It was a password spray on a legacy non-production tenant. From there? They pivoted to OAuth abuse to read the emails of Microsoft's own security leadership.
Supply Chain 2.0
SolarWinds was just the warm-up. They are now poisoning the trust relationships between Cloud Resellers (MSPs) and their downstream clients.
Why this matters to us
The financial impact isn't a ransom payment. It's the cost of "burning it down." When APT29 gets deep into your identity infrastructure, you often have to rebuild your entire Active Directory or Entra ID environment from scratch. That costs millions more than any Bitcoin ransom.
We’ve broken down their full history, their pivot to Cloud Identity attacks, and the specific Golden SAML technique in a full article and video.
👇 Deep Dive Here:
👇 Video:
0 comments