/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

ESET details a hacking campaign, active for the past 6 years, by the Russia-linked group the Dukes or Cozy Bear, which was thought to be dormant since DNC hack

Largely out of the spotlight since 2016, Cozy Bear hackers have been caught perpetrating a years-long campaign.

Wired Andy Greenberg

Context & Ripple Effects

After the DNC breach made Cozy Bear a household name, the group's trail went cold in the public record — apart from at least five phishing attacks on US NGOs and think tanks reported in late 2016, the Dukes were widely assumed to have stood down. ESET's new report dismantles that assumption: the group spent roughly six years running operations that no one published on.

The finding fits a pattern ESET itself has documented before, having exposed XDSpy, a group that operated undetected for nine years against government agencies. And within a year of this report, US sources attributed the hacks of the Treasury Department, NTIA, and FireEye to APT29 — the same Cozy Bear apparatus — confirming the group never paused, only lowered its profile.

First-order effects

  • Organizations in Cozy Bear's target set — governments, NGOs, think tanks — must treat their incident timelines as open-ended, since ESET's six-year window means compromises may predate any known indicator.
  • ESET gains attribution credibility from a named catch on one of espionage's most-watched groups, sharpening its role as the vendor surfacing long-dwell Russian operations.

Second-order effects

  • Other security vendors face pressure to re-examine their own telemetry for Dukes activity dating back to 2016, since a six-year blind spot implies industry-wide detection gaps rather than a single vendor's miss.
  • US government agencies already tracking APT29 — later confirmed behind the Treasury, NTIA, and FireEye intrusions — get a longer baseline for correlating the group's tooling across campaigns.

Third-order effects

  • If 'dormant' groups are actually operating below the publication threshold, defenders' mental model of threat-actor lifecycle breaks down: quiet periods signal stealth, not retirement, pushing the industry toward sustained retrospective hunting over headline-driven response.
  • Long-dwell campaigns that outlast news cycles make shared threat intelligence and ecosystem-level defense the only viable counterweight, since no single organization sees six years of activity on its own.

The trend: Russia-linked espionage groups like Cozy Bear increasingly run multi-year covert operations beneath the detection threshold, with vendor threat-intel reports periodically resetting the public timeline of their activity.

Discussion

  • @nordvpn @nordvpn on x
    Historical moment in cybersecurity. Russian hackers have been caught perpetrating a YEARS-long campaign: https://www.wired.com/... “The Dukes had penetrated the networks of at least three targets: the ministries of foreign affairs at two Eastern European countries.” via @wired ht…
  • @wired @wired on x
    A group of Russian hackers known as Fancy Bear stole the show during the 2016 breach of the Democratic National Committee. But a far quieter band of Kremlin hackers was inside DNC networks too. And they've been caught in the midst of another spy campaign. https://www.wired.com/..…
  • @a_greenberg Andy Greenberg on x
    Researchers at ESET found Russia's SVR hackers APT29/Cozy Bear back at it after years of relative quiet. They had penetrated three European countries' foreign ministries and planted malware that used clever steganography and stealth tricks. https://www.wired.com/...
  • @wired @wired on x
    “They rebuilt their arsenal ... They never stopped their espionage activity.” https://www.wired.com/...
  • @karolcummins Karol Cummins on x
    Stealthy Russian Hacker Group Resurfaces With Clever New Tricks Largely out of the spotlight since 2016, Cozy Bear hackers have been caught perpetrating a years-long campaign. https://www.wired.com/...
  • @issaintl @issaintl on x
    Old Bear learns new tricks - DNC hackers surface again. from @Wired https://www.wired.com/...