Void Blizzard

Aliases: LAUNDRY BEAR, UAC-0190, Laundry Bear

Origin
RU
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:21:59

Targeted industries: government-and-public-sector defense-and-aerospace transportation-and-logistics media-and-entertainment healthcare-and-pharmaceutical education-and-nonprofits

Targeted regions: country_code:fr country_code:de country_code:uk country_code:us country_code:ca

Context

Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America. The threat actor uses stolen credentials—which are likely procured from commodity infostealer ecosystems—and collects a high volume of email and files from compromised organizations.

Reports & references

  • Microsoft — New Russia Affiliated Actor Void Blizzard Targets Critical Sectors For Espionage (report)
  • aivd.nl — Onbekende Russische Groep Achter Hacks Nederlandse Doelen (report)
  • CERT-UA — 6286942 (report)
  • proofpoint.com — Cleaning Out Inboxes Ta488 Comes Outlook Another Half Click Exploit (report)
  • raw.githubusercontent.com — Microsoftmapping (report)

External references