logo

Malicious activities linked to the Nobelium intrusion set

ID: 3437c9ec-8192-4e0b-87d4-6081e0333b9f

STIX ID: report--3437c9ec-8192-4e0b-87d4-6081e0333b9f

Threat Score

90/100

Uploaded: 2026-07-29

Published Date: 2026-07-29

Last Modified Date: 2026-07-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:A1
...
...
ANSSI reports that the Nobelium intrusion set (also known as Midnight Blizzard), attributed to the Russian SVR, has been active since at least October 2020 and targets high-value diplomatic and IT-sector organizations for espionage. Operators use compromised legitimate email accounts and phishing lures to deliver private loaders and public tooling (e.g., Cobalt Strike), maintain persistence, and exfiltrate intelligence; recent activity includes campaigns against French diplomatic entities, breaches or email-exfiltration incidents involving Microsoft and HPE, and opportunistic exploitation of TeamCity (CVE-2023-42793). ANSSI highlights Nobelium as an ongoing, state-linked threat with published TTPs and IOCs available via partner reports.