A threat actor profile is only as good as its evidence base. Precision without evidence is fiction; uncertainty acknowledged is honest intelligence.
Threat Actor Profile Template
# THREAT ACTOR PROFILE
**Classification**: TLP:AMBER β Authorized recipients only
**Version**: 1.0 | **Last Updated**: 2024-09-01
**Profile Author**: [Your name/team]
---
## Summary
[2-3 sentence overview: who this actor is, what they do, why they matter to your organization]
## Identity
| Field | Value | Confidence |
|-------|-------|------------|
| Primary name | APT29 | High |
| Aliases | Cozy Bear, IRON HEMLOCK, Midnight Blizzard, Nobelium | High |
| Suspected sponsoring nation | Russia (SVR) | Moderate |
| Type | Nation-state | High |
| Motivation | Espionage | High |
## Targeting Profile
| Field | Value | Confidence |
|-------|-------|------------|
| Primary industries | Government, defense, think tanks, political | High |
| Geographic focus | Western Europe, North America, NATO members | High |
| Typical victims | Foreign policy organizations, intelligence targets | High |
| Relevance to us | [Assess whether this actor targets organizations like ours] | |
## Tactics, Techniques, and Procedures
### Initial Access
- T1566.002 Spearphishing Link [High confidence β documented in 5+ campaigns]
- T1195.002 Compromise Software Supply Chain [High β SolarWinds]
- T1078 Valid Accounts (stolen credentials via phishing) [High]
### Execution
- T1059.001 PowerShell [High]
- T1059.003 Windows Command Shell [Moderate]
### Persistence
- T1053.005 Scheduled Task [High]
- T1547.001 Registry Run Keys [Moderate]
[... continue for all tactics ...]
## Malware and Tools
| Tool | Type | Confidence | Notes |
|------|------|------------|-------|
| SUNBURST | Custom backdoor | High | SolarWinds supply chain |
| TEARDROP | Custom dropper | High | Post-SUNBURST payload |
| Cobalt Strike | Commercial | Moderate | Shared with many actors |
| MagicWeb | Custom ADFS backdoor | High | Attributed in 2022 |
## Infrastructure Patterns
- Hosting: Legitimate cloud services (Azure, AWS) for C2 blending
- Domain pattern: Typosquatting of target organization's third-party services
- Certificate: Let's Encrypt with target-relevant domain names
- Infrastructure lifecycle: Short-lived per operation; rotate after exposure
## Operational Patterns
- Active hours: Primarily UTC+3 business hours (Moscow timezone)
- Dwell time: Months to years (patience for high-value targets)
- Operational security: High β actively monitor for detection, change TTPs on discovery
## Known Campaigns
| Campaign | Dates | Victims | Objective |
|----------|-------|---------|-----------|
| SolarWinds | Oct 2019βJan 2021 | 18,000+ orgs (100 targeted) | Espionage/access |
| USAID phishing | May 2021 | NGOs, government | Credential theft |
| MagicWeb | 2022 | NATO-member governments | Persistent ADFS access |
## Intelligence Gaps
- Post-compromise tooling for newer campaigns: observed initial access,
limited visibility into full attack chains since 2022
- Infrastructure creation pipeline: how and where infrastructure is procured
- Full victim list: confirmed victims are a fraction of likely targets
## Sources
- [Mandiant APT29 profile URL]
- [Microsoft MSTIC Midnight Blizzard reporting]
- [CISA/NSA joint advisories]