APT29 (Cozy Bear / Midnight Blizzard, SVR) adversary-emulation playbook — malware-light cloud-identity espionage: no-MFA password spray, OAuth consent/token abuse, Golden SAML, mailbox collection over residential proxies. Use when emulating APT29 against an M365/Entra/AWS-identity estate. Triggers on: 'emulate APT29', 'Cozy Bear', 'Midnight Blizzard', 'NOBELIUM', 'OAuth abuse', 'cloud identity espionage', 'Golden SAML'.
74
92%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Tier-3 Russian SVR espionage actor. Emulate stealth cloud-identity tradecraft, not malware: APT29's modern signature is compromising identity (no-MFA password spray, device-code/consent phishing), abusing OAuth applications and tokens for persistence, and collecting mail/documents over residential proxies with a near-zero endpoint footprint. Authorized red-team emulation only — every action runs under the engagement RoE.
../../references/apt-groups.md).plan/threat-profile.json){
"engagement_name": "<fill>",
"actor_name": "APT29-like (Cozy Bear / Midnight Blizzard)",
"actor_aliases": ["Cozy Bear", "Midnight Blizzard", "NOBELIUM", "The Dukes", "UNC2452"],
"group_id": "G0016",
"tier": "tier-3",
"sophistication": "nation-state",
"motivation": "espionage",
"initial_access": ["T1078.004", "T1110.003", "T1566.002", "T1195.002"],
"key_ttps": ["T1528", "T1550.001", "T1098.001", "T1098.003", "T1606.002", "T1114.002", "T1071.001", "T1090.003", "T1070.004"],
"tools": ["AADInternals", "ROADtools", "TokenTactics", "Sliver", "residential proxies"],
"infrastructure": ["Engagement-owned OAuth apps (consent abuse)", "Residential proxy egress", "Low-and-slow Graph/API calls"],
"recent_cti_delta": "2024-2026: malware-light cloud tradecraft — malicious OAuth app consent, device-code phishing, password spray against legacy/no-MFA tenants (Microsoft + HPE corporate breaches); SolarWinds-style CI/CD supply-chain remains in repertoire.",
"confidence": "probable"
}Prune to RoE: if social engineering is out of scope, drop T1566.002; if only one cloud is
in scope, drop the others. A phase whose techniques are all pruned drops its kill-chain row.
Each row is a candidate OPPLAN objective. The orchestrator's OPPLAN-builder turns surviving
rows into add_objective calls; the executing agent loads the named skill.
| # | Phase | MITRE | Emulated action | Executing agent → skill |
|---|---|---|---|---|
| 1 | Recon | T1593 / T1589.002 | Map tenant, federation, employees, exposed apps/OWA, email format | recon → /skills/standard/recon/osint/SKILL.md, /skills/standard/recon/cloud-recon/SKILL.md |
| 2 | Initial Access | T1110.003 | Slow password spray against legacy/no-MFA cloud auth | exploit → /skills/standard/exploit/web/ato-methodology/SKILL.md |
| 3 | Initial Access (alt) | T1566.002 | Device-code / consent phishing (Teams/email lure) | phisher → /skills/standard/phisher/SKILL.md |
| 4 | Initial Access (alt) | T1195.002 | CI/CD or dependency supply-chain foothold | exploit → /skills/standard/exploit/supplychain/dep-confusion/SKILL.md |
| 5 | Credential/Token | T1528 / T1550.001 | Steal & replay OAuth app access tokens (skip password+MFA) | exploit → /skills/standard/exploit/web/oauth/SKILL.md |
| 6 | Persistence (cloud) | T1098.001 / T1098.003 | Add app credentials + high Graph roles; consent malicious OAuth app | cloud → /skills/standard/cloud/azure-managed-identity/SKILL.md, /skills/standard/cloud/aws-iam-passrole-chain/SKILL.md |
| 7 | Lateral (identity) | T1606.002 | Golden SAML / federation-trust token forgery | exploit → /skills/standard/exploit/web/saml/SKILL.md |
| 8 | Collection | T1114.002 | Mailbox / document collection via Graph (canary mailbox) | post-exploit → /skills/standard/post-exploit/credential-access/SKILL.md |
| 9 | C2 | T1071.001 / T1090.003 | Sliver beacon over HTTPS via residential proxy | post-exploit → /skills/standard/post-exploit/c2-sliver/SKILL.md |
| 10 | Exfiltration | T1567.002 | Low-and-slow exfil of scoped collection set | post-exploit → /skills/standard/post-exploit/reporting/SKILL.md |
Defense evasion (T1070.004 log/file cleanup, blending with admin activity) is cross-cutting —
the shared defense-evasion / opsec skills are auto-injected into every operational agent.
conops.json)Collapse the table into the 5-phase ObjectivePhase model:
recon — tenant/identity/federation enumeration (rows 1).initial-access — no-MFA password spray + consent phishing + optional supply-chain (2-4).post-exploit — token theft, cloud role/cred persistence, Golden SAML, mailbox collection (5-8).c2 — Sliver over HTTPS via residential proxy (9).exfiltration — scoped, throttled collection exfil (10).cleanup.json)./skills/standard/phisher/lure-deconfliction/SKILL.md).EMERGENCY abort trigger to abort.json: "real (non-canary) user mailbox or
document collected, or consent granted on a non-engagement OAuth app."redteam-<engagement-id>-* and record the app/client IDs
in deconfliction.json.If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.