New publication. APT29 (Cozy Bear).

APT29 (Cozy Bear) remains one of the most active cyber espionage groups linked to the Russian intelligence apparatus. Their approach is not built around “fast” attacks, but around long-term access, credential operations, and gradual persistence inside targeted infrastructure.

The report breaks down a typical APT29 attack chain — from OSINT collection, phishing delivery, and malicious RDP/HTML files to Azure AD compromise, persistence through service principals, and further activity within Office 365 and cloud environments. It also examines techniques repeatedly observed in recent campaigns, including DLL sideloading, HTML smuggling, OAuth token theft, MFA fatigue, and domain fronting.

[Read more]

New partnership

SHUM has established a partnership with Lex Talionis and OsintVarta as part of their joint OSINT-focused initiative.

The project brings together teams working on open-source investigations, data collection, and analytical research related to the russian federation’s defence-industrial complex and associated structures. It includes structured datasets, mapping, and analysis aimed at improving transparency and enabling further investigative work.

[Read more]

SHUM R&D Now Has a GitHub

Our Research and Development department has been running in the background for a while now — building tools and internal solutions that support our OSINT investigations and war crimes documentation efforts. As part of that, we’ve launched a GitHub organization. Access is restricted — our work touches sensitive areas, and we keep it that way intentionally. But if you’re a developer, researcher, or organization interested in what we’re building, feel free to reach out. We’re always open to conversation.

[Read more]

New publication. APT-Playbook.

This analytical report examines how GRU-linked APT groups operate in cyberspace as interconnected elements of a coordinated system rather than as isolated actors.

It reconstructs the operational logic behind units such as APT28 and APT44, showing how cyber operations are integrated with intelligence gathering, sabotage, and information campaigns. The analysis highlights that cyber activity is often driven by geopolitical triggers such as wars, elections, and crises, while different units perform distinct roles within a shared operational ecosystem.

[Read more]

Приватний розділ

Для доступу до приватного розділу введіть пароль:

Materials

Page 1 of 1
Page 1 of 1