Uptime Hamster: 11d 10h 15mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza SNOWGLOBE

SNOWGLOBE

0 incidentes 0 paises 0 sectores apt FR Ultimo: -
Aliases: ATK8, Animal Farm, sugieren una conexión con la región francesa
Ver en IntelTracker → APTTrail →
SNOWGLOBE, known also as APT29, Cozy Bear, and Midnight Blizzard, is a cyber espionage group attributed with high confidence to Russia's Foreign Intelligence Service (SVR). Active since at least 2008, the group operates with notable patience and operational discipline, often maintaining long-term access to compromised networks without detection. Their primary motivation is to collect intelligence that supports Russian foreign policy interests rather than financial gain or disruption. A defining characteristic of SNOWGLOBE is its evolving tradecraft, which increasingly leverages legitimate cloud services and "living off the land" techniques to blend its activities into normal network traffic, thereby weakening traditional security models. This approach includes a notable shift from endpoint-centric persistence to targeting identity systems, such as OAuth applications and SAML token manipulation, to bypass multi-factor authentication and ensure enduring access. The group gained significa

Aliases del actor

ATK8Animal Farmsugieren una conexión con la región francesa

Actores similares

contiransomware · 351ContFRransomware · 2lunalockransomware · 2iocontrolactor · 1apt-desertfalconactor · 1backconfigactor · 1redcontroleactor · 1apt-stealthfalconactor · 1Container and Resource Discoveryactor · 1Data from Configuration Repositoryactor · 1
Motivacion