← All Threat Actors
Threat Actor Profile

Void Blizzard

CL-STA-1114 LAUNDRY BEAR TA488 UAC-0185 UAC-0190 UNK_PitStop
▲ High Threat
Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America. The threat actor uses stolen credentials—which are likely procured from commodity infostealer ecosystems—and collects a high volume of email and files from compromised organizations.
Origin Russia

External Resources

CISA Advisories ↗

Related Intelligence


LINK COPIED TO CLIPBOARD