Also known as: LAUNDRY BEAR, UAC-0190, TA488, Laundry Bear
Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America. The threat actor uses stolen credentials—which are likely procured from commodity infostealer ecosystems—and collects a high volume of email and files from compromised organizations.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Void Blizzard is a high-sophistication cyberespionage threat actor likely linked to Russian-speaking groups. They primarily target critical sectors in the U.S. and Europe through credential theft and data exfiltration campaigns, often leveraging commodity tools in conjunction with custom tactics. Their operations have been observed deploying phishing and OSINT techniques to compromise organizations for intelligence gathering purposes.
Goals & Targeting
Void Blizzard's primary objective appears to be intelligence gathering on behalf of Russian state interests. They target sectors with critical infrastructure and geopolitical importance, likely to align with Russian strategic priorities. Their focus on U.S. organizations suggests a desire to gather information on domestic policies, military planning, or technological developments that could impact Russia's global standing.
Enhanced Description
Void Blizzard engages in highly targeted cyberespionage activities, focusing on sensitive industries such as government, defense, healthcare, and energy sectors, primarily within the United States. The group appears to leverage a mix of commodity tools and custom malware to infiltrate targets, often using stolen credentials obtained via infostealer ecosystems. Their operations are characterized by data collection from compromised systems, particularly targeting email accounts and sensitive files. Mitigating their threats requires robust authentication mechanisms, continuous monitoring for known TTPs, and proactive threat hunting in the network.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Void Blizzard has been observed conducting multiple campaigns targeting U.S. and European organizations since at least 2019. Their operations often involve initial compromise through phishing or OSINT-based techniques, followed by extensive credential collection and lateral movement within networks. Notable past operations include high-profile compromises of government agencies and critical infrastructure entities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Void Blizzard's affiliation with Russian-speaking groups is high, given their targeting patterns and use of tools linked to similar actors. However, specific details about their exact origins and direct ties to Russian intelligence remain speculative. Additional clarity on their technical capabilities beyond commodity tools would enhance understanding.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
10
IOCs
0
Observed Data
0
Tactics