ESET details a hacking campaign, active for the past 6 years, by the Russia-linked group the Dukes or Cozy Bear, which was thought to be dormant since DNC hack
Largely out of the spotlight since 2016, Cozy Bear hackers have been caught perpetrating a years-long campaign.
Context & Ripple Effects
After the DNC breach made Cozy Bear a household name, the group's trail went cold in the public record — apart from at least five phishing attacks on US NGOs and think tanks reported in late 2016, the Dukes were widely assumed to have stood down. ESET's new report dismantles that assumption: the group spent roughly six years running operations that no one published on.
The finding fits a pattern ESET itself has documented before, having exposed XDSpy, a group that operated undetected for nine years against government agencies. And within a year of this report, US sources attributed the hacks of the Treasury Department, NTIA, and FireEye to APT29 — the same Cozy Bear apparatus — confirming the group never paused, only lowered its profile.
First-order effects
- Organizations in Cozy Bear's target set — governments, NGOs, think tanks — must treat their incident timelines as open-ended, since ESET's six-year window means compromises may predate any known indicator.
- ESET gains attribution credibility from a named catch on one of espionage's most-watched groups, sharpening its role as the vendor surfacing long-dwell Russian operations.
Second-order effects
- Other security vendors face pressure to re-examine their own telemetry for Dukes activity dating back to 2016, since a six-year blind spot implies industry-wide detection gaps rather than a single vendor's miss.
- US government agencies already tracking APT29 — later confirmed behind the Treasury, NTIA, and FireEye intrusions — get a longer baseline for correlating the group's tooling across campaigns.
Third-order effects
- If 'dormant' groups are actually operating below the publication threshold, defenders' mental model of threat-actor lifecycle breaks down: quiet periods signal stealth, not retirement, pushing the industry toward sustained retrospective hunting over headline-driven response.
- Long-dwell campaigns that outlast news cycles make shared threat intelligence and ecosystem-level defense the only viable counterweight, since no single organization sees six years of activity on its own.
The trend: Russia-linked espionage groups like Cozy Bear increasingly run multi-year covert operations beneath the detection threshold, with vendor threat-intel reports periodically resetting the public timeline of their activity.