← Back to Research
Threat Reports

Cozy Bear's New Claws: APT29 Shifts Tactics in European Targeting

AuthorThreat Research Team
PublishedOct 12, 2024

This is a comprehensive placeholder for the technical report. In a production environment, this would be fetched from a CMS like Sanity, Contentful, or directly from Markdown files.


APT29 (also known as Cozy Bear) has evolved their tooling significantly. Recent intrusions reveal a departure from their historical reliance on complex malware frameworks in favor of heavily obfuscated scripting languages and abuse of native administrative tools.


Indicators of Compromise

  • 192.168.1.1 (Example IP)
  • malicious.exe (SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855)