Dark Halo is a state-sponsored espionage threat actor linked to intrusions against a US-based think tank and associated with activity overlapping the SolarWinds supply-chain compromise. The group has been publicly connected in reporting to UNC2452 and, by anonymous government sourcing cited in major media, to APT29/Cozy Bear, a cluster widely believed to be tied to Russia. Dark Halo has been described as highly skilled, persistent, and capable of maintaining long-term access while minimizing forensic visibility. Observed operations show a strong focus on intelligence collection, especially theft of email from selected executives, policy experts, and IT personnel. In one environment, the actor conducted multiple separate intrusions over several years, returned after apparent eviction, and used both malware and living-off-the-land techniques. Reported tradecraft included exploitation of Microsoft Exchange Control Panel for re-entry, abuse of Exchange administrative tooling and PowerShell cmdlets for reconnaissance and post-compromise operations, use of scheduled tasks for lateral movement, mailbox export operations to collect targeted mail, manipulation of ActiveSync settings to authorize attacker-controlled devices, and cleanup actions to remove evidence after collection. Dark Halo also demonstrated the ability to bypass Duo-protected multi-factor authentication in Outlook Web Access after deep compromise of the server-side environment. Rather than exploiting a product vulnerability or hijacking an existing session, the actor obtained the Duo integration secret from the compromised server and used it to generate a valid MFA-related session value, allowing access when combined with valid user credentials. This reflects mature post-exploitation capability, credential abuse, defense evasion, and a detailed understanding of enterprise authentication integrations. Malware associated with the actor includes Sunshuttle. Dark Halo has also been tied to infrastructure and operational overlap with the broader SolarWinds campaign. Overall, the actor is best characterized as a sophisticated Russian-linked espionage operator focused on stealthy access, credentialed abuse of enterprise services, and selective exfiltration of high-value communications.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
69 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the threat actor associated with the Sunshuttle malware sample used as an example in a reverse-engineering workshop on Go binaries.
Compromised an OWA server and bypassed Duo-protected MFA by obtaining the Duo integration secret key (akey) from the server and forging a valid duo-sid cookie after successful password authentication.
State-sponsored threat actor linked here to the supply chain attack that compromised public and private organizations. The group repeatedly penetrated a think tank, maintained long-term undetected access, and bypassed Duo MFA by stealing the Duo integration secret key (akey) from an Outlook Web App server and generating a valid duo-sid cookie.
Conducted repeated intrusions into a think tank and used privileged access on an Outlook Web App server to steal a Duo integration secret (akey), generate a valid duo-sid cookie, and bypass MFA in order to access targeted email accounts and remain undetected for extended periods.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.