APT29 // MIDNIGHT BLIZZARD
SVR RUSSIAN FEDERATION
Target Sectors: Defense Industrial Base, Cloud Identity Tenants, Foreign Affairs
Primary TTPs: OAuth App Consent Abuse (T1098.005), Token Theft via Graph API, Residential Proxy Egress
Active Weapon: MagicWeb AD FS DLL injection (`Microsoft.IdentityServer.Diagnostics.dll`)
IoC: 185.161.211.74:443 | auth-protection-microsoft.com