Void Blizzard
Aliases: LAUNDRY BEAR, UAC-0190, Laundry Bear
- Origin
- RU
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:21:59
Targeted industries: government-and-public-sector defense-and-aerospace transportation-and-logistics media-and-entertainment healthcare-and-pharmaceutical education-and-nonprofits
Targeted regions: country_code:fr country_code:de country_code:uk country_code:us country_code:ca
Context
Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America. The threat actor uses stolen credentials—which are likely procured from commodity infostealer ecosystems—and collects a high volume of email and files from compromised organizations.
Reports & references
- Microsoft — New Russia Affiliated Actor Void Blizzard Targets Critical Sectors For Espionage (report)
- aivd.nl — Onbekende Russische Groep Achter Hacks Nederlandse Doelen (report)
- CERT-UA — 6286942 (report)
- proofpoint.com — Cleaning Out Inboxes Ta488 Comes Outlook Another Half Click Exploit (report)
- raw.githubusercontent.com — Microsoftmapping (report)