Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Void Blizzard

Also known as: LAUNDRY BEAR, UAC-0190, TA488, Laundry Bear

Description

Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America. The threat actor uses stolen credentials—which are likely procured from commodity infostealer ecosystems—and collects a high volume of email and files from compromised organizations.

Goals & Targeting

Targeted Sectors

Education
Financial services
Government
Healthcare
Manufacturing
Retail
Energy

Targeted Countries / Regions

United States of America

AI Analysis

· 1 week ago

Executive Summary

Void Blizzard is a high-sophistication cyberespionage threat actor likely linked to Russian-speaking groups. They primarily target critical sectors in the U.S. and Europe through credential theft and data exfiltration campaigns, often leveraging commodity tools in conjunction with custom tactics. Their operations have been observed deploying phishing and OSINT techniques to compromise organizations for intelligence gathering purposes.

Goals & Targeting

Void Blizzard's primary objective appears to be intelligence gathering on behalf of Russian state interests. They target sectors with critical infrastructure and geopolitical importance, likely to align with Russian strategic priorities. Their focus on U.S. organizations suggests a desire to gather information on domestic policies, military planning, or technological developments that could impact Russia's global standing.

Enhanced Description

Void Blizzard engages in highly targeted cyberespionage activities, focusing on sensitive industries such as government, defense, healthcare, and energy sectors, primarily within the United States. The group appears to leverage a mix of commodity tools and custom malware to infiltrate targets, often using stolen credentials obtained via infostealer ecosystems. Their operations are characterized by data collection from compromised systems, particularly targeting email accounts and sensitive files. Mitigating their threats requires robust authentication mechanisms, continuous monitoring for known TTPs, and proactive threat hunting in the network.

Key Capabilities

  • Credential theft via infostealers
  • Phishing campaigns using stolen credentials
  • Data exfiltration from targeted systems
  • Usage of commodity and custom tools for persistence and lateral movement

MITRE ATT&CK Tactics

Espionage
Defense Evasion
Credential Access

ATT&CK Techniques

T1566.001
T1233.001
T1078.002
T1564.001

Software / Tooling

Cobalt Strike
Mimikatz
Custom infostealers

Campaigns & Victims

Void Blizzard has been observed conducting multiple campaigns targeting U.S. and European organizations since at least 2019. Their operations often involve initial compromise through phishing or OSINT-based techniques, followed by extensive credential collection and lateral movement within networks. Notable past operations include high-profile compromises of government agencies and critical infrastructure entities.

IOC Patterns

  • Spear-phishing emails targeting executives and employees
  • C2 communication using compromised domains
  • Staging servers linked to known Russian-speaking groups
  • Harvested credentials appearing on OSINT platforms

Recommended Actions

  • Implement multi-factor authentication (MFA) for critical systems
  • Monitor for known Void Blizzard TTPs in network traffic
  • Conduct regular employee training on phishing and OSINT risks
  • Use threat intelligence feeds to block associated domains
  • Deploy endpoint detection and response (EDR) solutions
  • Enhance email filtering and DMARC policies
  • Share threat data with sector-specific ISACs

Suggested Tags

APT
espionage
cyber-espionage
government-targeted
nation-state
OSINT

Confidence Assessment

Confidence in Void Blizzard's affiliation with Russian-speaking groups is high, given their targeting patterns and use of tools linked to similar actors. However, specific details about their exact origins and direct ties to Russian intelligence remain speculative. Additional clarity on their technical capabilities beyond commodity tools would enhance understanding.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

10

IOCs

0

Observed Data

0

Tactics

Tags

APT
Healthcare Targeting
Government Targeting
espionage
cyber-espionage
government-targeted
nation-state
OSINT

Details

Type
Criminal
Country of Origin
R
Confidence
70%
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.