Official ATT&CK groups · sourced comparison
Documented group behavior. Independent vehicle evidence.
Select a known ATT&CK group to inspect its sourced behavior path. A vehicle path appears only when accepted SBOM and canary records bind to that VIN.
APT29
Also tracked as Blue Kitsune · Cozy Bear · CozyDuke · Dark Halo · IRON HEMLOCK · IRON RITUAL · Midnight Blizzard · NOBELIUM · NobleBaron · SolarStorm · The Dukes · UNC2452 · UNC3524 · YTTRIUM
[APT29](https://attack.mitre.org/groups/G0016) is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).(Citation: White House Imposing Costs RU Gov April 2021)(Citation: UK Gov Malign RIS Activity April 2021) They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. [APT29](https://attack.mitre.org/groups/G0016) reportedly compromised the Democratic National Committee starting in the summer of 2015.(Citation: F-Secure The Dukes)(Citation: GRIZZLY STEPPE JAR)(Citation: Crowdstrike DNC June 2016)(Citation: UK Gov UK Exposes Russia SolarWinds April 2021) In April 2021, the US and UK governments attributed the [SolarWinds Compromise](https://attack.mitre.org/campaigns/C0024) to the SVR; public statements included citations to [APT29](https://attack.mitre.org/groups/G0016), Cozy Bear, and The Dukes.(Citation: NSA Joint Advisory SVR SolarWinds April 2021)(Citation: UK NSCS Russia SolarWinds April 2021) Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.(Citation: FireEye SUNBURST Backdoor December 2020)(Citation: MSTIC NOBELIUM Mar 2021)(Citation: CrowdStrike SUNSPOT Implant January 2021)(Citation: Volexity SolarWinds)(Citation: Cybersecurity Advisory SVR TTP May 2021)(Citation: Unit 42 SolarStorm December 2020)
Attribution boundary
Public ATT&CK identity and procedure records only. No relationship to Northstar, a customer, supplier, or selected VIN is asserted.
Official identity source
MITRE ATT&CK · G0016- ATT&CK record
- G0016
- Record version
- 6.2
- Created
- Unknown
- Last modified
- Unknown
- Catalogue release
- 19.2
- Replay fixture
- AL-BUILD-TRUST-1.1.0
- Technique overlaps
- 02
- Mapped events
- 05
- Evidence gates
- 10
- Defensive analytics
- 02
Operational sequence assessment
The active MITRE ATT&CK Enterprise release maps APT29 to T1070.004 Indicator Removal: File Deletion. Consult the official group record for its cited procedure examples.
Public behavior is a comparison lens · Northstar events below are synthetic · no attribution
Synthetic replay lane · not VIN evidence
Reached and failed counts below evaluate only the fixed Northstar fixture. They cannot open a vehicle path or establish group presence.
NO VIN
Independent VIN gates
Reached
0/3
Failed gates
0/3
Pending
3/3
Coverage gaps
0/3
- 1
- 2
- 3
Select a VIN to build this group’s full evidence path.
A VIN supplies the scope for SBOM, release-manifest and canary evidence. Group behavior remains a separate comparison lens.
Select VINExact ATT&CK joins
Public behavior mapped to fixture observations
Technique context retained
T1070.004 is highlighted below. Public group behavior remains separate from synthetic replay evidence.
PATH 01
T1070.004
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps APT29 to T1070.004 Indicator Removal: File Deletion. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E14 to E28
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E1413:00Build interpositionFile integrity
Workspace restored to the committed state
The fixture is removed and the workspace again matches the commit. Post-build inspection of the workspace now shows nothing — the window has closed.
BLD-WIN-03
- E1615:00Build interpositionFile integrity
Short-lived file mutation recorded, not alerted
File-integrity monitoring recorded create and delete inside the workspace but the workspace path is excluded from alerting. The evidence existed; the rule did not.
BLD-WIN-03
- E2824:30InvestigationFile integrity
Transient workspace mutation recovered from raw records
The create/delete pair is still in the raw file-integrity stream even though no alert fired. Retention, not alerting, saved this investigation.
BLD-WIN-03
PATH 02
T1078.004
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps APT29 to T1078.004 Valid Accounts: Cloud Accounts. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E05 to E06
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0504:00Build accessIdentity
Build access — an existing automation session is reused
The scenario grants the emulation a pre-existing automation session on the build tier. How that session was obtained is deliberately out of scope: this exercise studies what happens after trust is already held.
CI-ORCH-01
- E0605:00Build accessIdentity
Automation identity used outside its schedule
The automation identity authenticates 43 minutes outside its recorded schedule window. Schedule deviation for non-human identities is a high-value, low-noise signal.
CI-ORCH-01