Skip to content
Weekly Signal

Automated evidence cluster

APT29: Defence targeting activity

Automatically correlated reporting linking APT29 to activity affecting Defence. Review the supporting sources before treating attribution as confirmed.

69% correlation confidence.This grouping supports investigation. It is not a definitive attribution or a vendor-assigned campaign name.
3Reports
2Sources
90Highest signal
20 Aug 2026Latest activity

Actors in supporting reports

APT29STORM-2945UNC5976UNC6293UNC7005APT15APT20APT27APT28APT30APT31APT33APT34APT35APT37APT39APT40APT41APT42APT44APT45FIN7SandwormUNC1069UNC1088UNC2814UNC4057

Supporting evidence

Google Threat Intelligence Group · 24 Jul 2026

Updated Cyber Threat Actor Naming System ↗

Update (July 30): A table listing the new names of select prominent threat actors was appended to this post.  Introduction  Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors.…

49

Palo Alto Networks Unit 42 · 20 Aug 2026

Identity Abuse Through Trusted Communication Channels ↗

Threat Research CenterThreat ResearchMalware Malware Identity Abuse Through Trusted Communication Channels 12 min read Related ProductsCortexCortex XDRCortex XSIAMIdiraUnit 42 Incident Response By:Bill Batchelor Published:August 20, 2026 Categories:MalwareThreat Research Tags:AuthenticationIdentity theftMalwareMFARemote access softwareSocial engineering Share Executive Summary Identity has…

37