SVR
SVR is Russia’s Foreign Intelligence Service and is described in the content as a Russian state intelligence service responsible for cyber espionage activity. The content links SVR cyber actors with the aliases APT29, the Dukes, Cozy Bear, NOBELIUM, and Midnight Blizzard. Reported activity includes the 2020 SolarWinds supply-chain compromise and broader follow-on intrusions into U.S. government, critical infrastructure, and private-sector organizations, which the U.S. Government attributed to the SVR in April 2021. In that campaign, the actor used a trojanized SolarWinds Orion DLL signed with SolarWinds’ legitimate certificate, SUNBURST malware with DNS-based command and control, and additional access methods beyond SolarWinds including password spraying, password guessing, abuse of externally exposed administrative credentials, and SAML token abuse. The content also states the actor abused compromised or spoofed authentication tokens, added tokens and certificates to Azure and Microsoft 365 service principals, modified federation trusts, compromised SAML signing certificates, targeted email accounts of key personnel, and used anti-forensic and stealth techniques. CISA assessed the actor as patient, well-resourced, focused, and capable of sustained long-duration operations. The content also states that SVR cyber actors exploited JetBrains TeamCity vulnerability CVE-2023-42793 at large scale beginning in September 2023, targeting unpatched, internet-reachable on-premises TeamCity servers globally. Authorities assessed this access could enable software supply-chain compromise, though they said they had not observed SolarWinds-like downstream attacks from this activity. Observed post-exploitation behavior included privilege escalation, lateral movement, persistence via scheduled tasks, credential theft, Active Directory enumeration, registry hive exfiltration, use of Mimikatz, use of Rubeus, use of WinPEAS, disabling antivirus and EDR including via BYOVD techniques and EDRSandBlast, and deployment of additional backdoors. The content specifically identifies the GraphicalProton backdoor, including variants using DLL hijacking in Zabbix, hiding activity in vcperf, and using Microsoft OneDrive and Dropbox for command and control and data exchange, with data obfuscated inside randomly generated BMP files. The advisory cited in the content says cybersecurity companies and governments have reported SVR operations targeting networks to steal confidential and proprietary information since 2013. The content further mentions that the SVR allegedly hacked the Democratic National Committee network in 2015, although it was not named in the 2018 Mueller indictment focused on GRU activity.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Software & Services
- Utilities
- Military
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇳🇱 Netherlands
- 🇺🇦 Ukraine
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
Associated vulnerabilities
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The U.S. Federal Bureau of Investigation (FBI), ... assess Russian Foreign Intelligence Service (SVR) cyber actors ... are exploiting CVE-2023-42793 at a large scale, targeting servers hosting JetBrains TeamCity software since September 2023.
"By exploiting multiple Pulse Secure VPN weaknesses (CVE-2019-11510, CVE-2020-8260, CVE-2020-8243, and CVE-2021-22893), UNC2630 is said to have harvested login credentials..." ... "...advisory, warning businesses of active exploitation of five publicly known vulnerabilities by the Russian Foreign Intelligence Service (SVR), including CVE-2019-11510..."
Observables
161 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed (in this content) with the 2020 SolarWinds supply-chain compromise enabling long-term access into multiple Western government agencies.
Referenced for adapting tactics to obtain initial access in cloud environments.
Exploited a TeamCity vulnerability (CVE-2023-42793) to gain access, move laterally within victim networks, and deploy backdoors (GraphicalProton) to enable follow-on operations.
Exploiting JetBrains TeamCity (CVE-2023-42793) at scale to gain initial access, establish footholds, deploy stealthy C2 (including via legitimate cloud services), and plant additional backdoors after privilege escalation and lateral movement; historically focused on long-term intelligence collection and has conducted supply-chain style operations (e.g., SolarWinds).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.