Void Blizzard
0 incidentes
0 paises
0 sectores
apt RU Ultimo: -
Aliases: LAUNDRY BEAR, UAC-0190
Void Blizzard is a Russian state-backed cyberespionage group that has been active since at least April 2024, focusing on intelligence gathering to support Russian strategic objectives. The group was publicly identified in May 2025 by Microsoft Threat Intelligence and Dutch intelligence agencies. While officially tracked as Void Blizzard by Microsoft, it is also known as LAUNDRY BEAR by Dutch intelligence and UAC-0190 by CERT-UA. The group's primary motivation is cyberespionage, specifically targeting sensitive data related to military production, procurement, and weapons deliveries to Ukraine. What sets Void Blizzard apart is its high success rate despite relying on relatively unsophisticated techniques, primarily abusing legitimate cloud services and employing a "living off the land" approach, rather than using complex custom malware. They are assessed with high confidence to be linked to the Russian state, potentially affiliated with the GRU, and are distinct from other well-known Ru