Deep Dive into the Intrusion of APT29: Analyzing Initial Access and Techniques of Operation
James Calloway — Threat Hunter Key TakeawaysAPT29 utilizes phishing as a primary vector for initial access, often leveraging credential harvesting tools.The group employs resourcing techniques including custom malware such as CozyBear to maintain persistence and…