Netskope Threat Labs

Nobelium

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Nobelium (a.k.a. APT29, Cozy Bear) is a Russian state sponsored threat actor group known for sophisticated supply chain attacks and espionage campaigns. Its operations include the SolarWinds compromise, which planted backdoors in trusted software updates and reached thousands of downstream organizations, and its tradecraft emphasizes patience, credential theft, and abuse of legitimate cloud services. The group's tooling and tactics continually evolve, and defenders treat its name as a marker of the most capable espionage operations.

First seen
March 2022
Last seen
September 2026
Alert Name
DeepScan:Generic.HTML.Nobelium.A.FFFFFFFE
Generic.HTML.Nobelium.A.085BA0E4
Generic.HTML.Nobelium.A.08E1D94C
Generic.HTML.Nobelium.A.114B8323
Generic.HTML.Nobelium.A.15CC815F
Generic.HTML.Nobelium.A.1B96B653
Generic.HTML.Nobelium.A.4F6E2170
Generic.HTML.Nobelium.A.5C02F195
Generic.HTML.Nobelium.A.62768855
Generic.HTML.Nobelium.A.64639038