RU

Void BlizzardVoid Blizzard

Also known as: LAUNDRY BEAR · UAC-0190 · Void Blizzard

Origin
RU
Known aliases
3

Profile

Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America. The threat actor uses stolen credentials—which are likely procured from commodity infostealer ecosystems—and collects a high volume of email and files from compromised organizations.

Aliases· 3

LAUNDRY BEARUAC-0190Void Blizzard

References

  1. https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/
  2. https://www.aivd.nl/actueel/nieuws/2025/05/27/onbekende-russische-groep-achter-hacks-nederlandse-doelen
  3. https://cert.gov.ua/article/6286942

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Void Balaur
Actor
Void Rabisu
Actor
Winter Vivern
Actor
Sunglow Blizzard
Actor
Void Manticore
Software
VoidCrypt
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.