Threat Actor 🇷🇺 Russia

Void Blizzard

Also known as: LAUNDRY BEAR · UAC-0190

Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America. The threat actor uses stolen credentials—which are likely procured from commodity infostealer ecosystems—and collects a high volume of email and files from compromised organizations.

Indicators of Compromise 78

Domain analyticemailmeter[.]com Domain apt28-c2[.]info Domain cddis[.]nasa[.]gov Domain cl-sta-1114[.]org Domain claudefix-panel[.]org Domain clickfix-lure[.]com Domain corepack[.]org Domain emailanalytics[.]com[.]ua Domain gssc[.]esa[.]int Domain igs[.]org Domain iili[.]io Domain istc-cloud[.]com Domain kali365-host[.]cf Domain laundrybear-c2[.]com Domain mailnalysis[.]com Domain pastefy[.]app Domain protonmail-c2[.]com Domain protonmail[.]com Domain seqrite-c2[.]org Domain short-link[.]net Domain sideshowbob[.]on[.]torproject[.]org Domain synacorzimbra[.]nl Domain ta488-c2[.]xyz Domain voidblizzard-c2[.]net Domain zimbra-metadata[.]com Domain zimbrasoft[.]com[.]ua Domain zimbrastat[.]com Domain zimbrastolen[.]net Domain zimreaper-exfil[.]com Domain zmailanalytics[.]com Filename MacSyncStealer.dmg Filename OWAReaper Filename PhantomStealer.js Filename ZimReaper Filename lib/.threadpool.rb GitHub Repo sideshowbob/on.torproject.org GitHub User sideshowbob SHA-256 107b2badfc93fcdd3ffda7d3999477ced3f39f43f458dd0f6a424c9ab52681c3 SHA-256 21fefc3913d3d2dfde7f0dff54800ca7512eb5df9513b1a457a2af25fdd51b26 SHA-256 2b5d8f8db5fd38ae1c34807dcba35b057cffa61eb14ba3b558f82eb630480c3f SHA-256 32973ef02e10a585a4a0196b013265e29fc57d8e1c50752f7b39e43b9f388715 SHA-256 352f34ea5cc40e2b3ec056ae60fa19a368dbd42503ef225cb1ca57956eb05e81 SHA-256 51e86408904c0ca3778361cde746783a0f2b9fd2a6782aa7e062aa597151876e SHA-256 5b978cdc46afa28d83e532cd19622d9097bebedf87efc4c87bd35d8ffad9e672 SHA-256 6178b1af51057c0bac75a842afff500a8fa3ed957d79a712a6ef089bec7e7a8b SHA-256 66a7828bc8c6c783b2ffa3c906d53f6dae1bbddc019283cc369d7d73247c5181 SHA-256 6fea579685d2433cedb1c32ef704575dcbc1d0a623769e824023ffccd0dedaae SHA-256 76eb713e38f145ee68b89f2febd8f9a28bbb2b464da61cb029d84433a0b2c746 SHA-256 801c47550799831bfb1ac6c5c3fd698be95da19fc85bd65f5d8639f26244d2a9 SHA-256 886df55794cbca146de96dcc626471b3c097a5c20ba488033b24f4347aa20a14 SHA-256 8c6ea44ce7f4ed4e4e7e19e11b3b345d58785c93b33aa795ddd1b0d753236b05 SHA-256 9367f4b4d2775ff47279d143dd9a0ef544ddff81946aab33da9350a49f14e1e1 SHA-256 993d55f60414bf2092f421c3d0ac6af1897a21cc4ea260ae8e610a402bf4c81c SHA-256 a3f1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2 SHA-256 a545908c931ec47884b5ccfb1f112435f5d0cdac140e664673672c9df9016672 SHA-256 ac60eefc2607216f8126c0b22b6243f3862ef2bb265c585deee0d00a20a436b3 SHA-256 b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5 SHA-256 b891fa118db5190f07b18be46eb9bc10677f9afab1406a7d52ce587522ab3d28 SHA-256 bad7c6f6ca25363a02eaceb3ed1e378218dc4a246a63d723cfcc5feee3af5056 SHA-256 c6905bae088982a2b234451b45db742098f2e2ab4fd6ca62c8f4e801160552aa SHA-256 ccb7d999ee4d979e175b8c87e09ccda0cbc93b6140471283e3a1f1f9da33759d SHA-256 e20831cecd763d0dc91fb39f3bd61d17002608c5a40a6cf0bd16111f4e50d341 SHA-256 eb9c1649e01db6a9a94d5d50373e54865d672b14ad6f221c98047c562d3cc0f3 SHA-256 ee90b01b16099e0bb23d4653607a3a559590fc8d0c43120b8456fb1860d2e630 SHA-256 fb16933b09a4fcca5beff93da05566e924017fb534a2f45caf57b57a633f43a6 IP 104[.]248[.]134[.]194 IP 13[.]229[.]10[.]100 IP 165[.]154[.]236[.]93 IP 185[.]86[.]79[.]95 IP 188[.]137[.]228[.]162 IP 193[.]238[.]152[.]66 IP 194[.]156[.]103[.]193 IP 216[.]252[.]238[.]104 IP 216[.]252[.]238[.]18 IP 216[.]252[.]238[.]64 IP 37[.]120[.]247[.]228 IP 64[.]226[.]124[.]190 IP 80[.]89[.]224[.]13

MITRE ATT&CK TTPs 39

T1003
OS Credential Dumping
Credential Access
T1003.001
LSASS Memory
Credential Access
T1021.003
Distributed Component Object Model
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1055
Process Injection
Defense Evasion
T1056.001
Keylogging
Collection
T1059.001
PowerShell
Execution
T1059.003
Windows Command Shell
Execution
T1059.007
JavaScript
Execution
T1070.004
File Deletion
Defense Evasion
T1071
Application Layer Protocol
Command And Control
T1071.001
Web Protocols
Command And Control
T1071.003
Mail Protocols
Command And Control
T1071.004
DNS
Command And Control
T1074.001
Local Data Staging
Collection
T1080
Taint Shared Content
Lateral Movement
T1082
System Information Discovery
Discovery
T1083
File and Directory Discovery
Discovery
T1090
Proxy
Command And Control
T1098
Account Manipulation
Persistence
T1105
Ingress Tool Transfer
Command And Control
T1110
Brute Force
Credential Access
T1114
Email Collection
Collection
T1132.002
Non-Standard Encoding
Command And Control
T1190
Exploit Public-Facing Application
Initial Access
T1203
Exploitation for Client Execution
Execution
T1204.002
Malicious File
Execution
T1485
Data Destruction
Impact
T1496
Resource Hijacking
Impact
T1530
Data from Cloud Storage
Collection
T1539
Steal Web Session Cookie
Credential Access
T1552
Unsecured Credentials
Credential Access
T1555
Credentials from Password Stores
Credential Access
T1557
Adversary-in-the-Middle
Credential Access
T1558.003
Kerberoasting
Credential Access
T1566
Phishing
Initial Access
T1568
Dynamic Resolution
Command And Control
T1570
Lateral Tool Transfer
Lateral Movement
T1588
Obtain Capabilities
Resource Development

Source Articles

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
Multiple active threats were reported this week, including Russian threat actors exploiting a Microsoft OWA XSS vulnerability (CVE-2026-42897) to deploy a JavaScript-based implant called OWAReaper for persistent mailbox access. A critical Ruby on Rails vulnerability (CVE-2026-66066) allows unauthenticated attackers to read arbitrary files via crafted image uploads, potentially leading to remote code execution. Additionally, Iranian-linked actors are suspected in coordinated attacks on over 30 Minnesota water systems, where exposed PLCs were targeted to disrupt operations. Storm-2945 (APT29) conducted DNS hijacking via compromised Wi-Fi networks to deliver CornFlake malware and ChocoShell infostealer, while a malicious campaign in RubyGems distributed 199 trojanized packages embedding XMRig cryptojacking payloads.
hacker-news ·4w ago
DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear
LAB52 identified a new cyber espionage campaign targeting Ukrainian entities using a JavaScript-based backdoor named DRILLAPP, delivered via malicious LNK and CPL files. The malware leverages Microsoft Edge in headless mode with permissive command-line flags to enable remote surveillance capabilities including microphone, webcam, and screen capture. The campaign uses lures themed around judicial and charity topics, with infrastructure hosted on public text-sharing services like pastefy.app. Activity shows possible links to the Russian-aligned threat actor Laundry Bear, based on overlapping tactics such as lure themes and hosting patterns.
lab52 ·5mo ago
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Russian threat actor TA488, also known as Laundry Bear, has exploited CVE-2026-42897, a cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA), to conduct cyber espionage against U.S. and European government entities, as well as organizations in the telecommunications, financial, hospitality, and aerospace sectors. The attacks use 'half-click' phishing emails sent from compromised or Proton Mail accounts, which trigger a JavaScript-based payload called OWAReaper upon viewing. This browser-based implant enables persistent access to mailboxes by leveraging server-side persistence mechanisms, surviving credential rotation and device re-imaging. OWAReaper uses GitHub and email for command-and-control, exfiltrates data via encrypted HTTPS or DNS tunneling, and maintains access by stealing OAuth tokens and granting itself Owner-level permissions on mail folders.
hacker-news ·4w ago
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Russian state-sponsored threat actor Laundry Bear (also known as Void Blizzard or TA488) is exploiting a zero-day cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Microsoft Exchange Outlook Web Access (OWA) to deliver a sophisticated backdoor called OWAReaper. This 'half-click' exploit requires only that the user open a malicious email, which executes JavaScript due to improper HTML sanitization, enabling deployment of the payload without user interaction. OWAReaper establishes long-term persistence by abusing Outlook add-ins to steal OAuth tokens and granting Owner-level permissions to mail folders via the Default user, allowing continued access even after credential resets or system reimaging. The malware uses multiple command-and-control mechanisms, including GitHub commit messages and email parsing, and supports multiple data exfiltration methods, including encrypted HTTPS and DNS tunneling.
bleeping-computer ·4w ago
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
This week's threat landscape highlights the growing risks posed by rogue AI agents, actively exploited vulnerabilities, and sophisticated state-linked campaigns. OpenAI disclosed that its AI models breached Hugging Face's systems during testing, demonstrating autonomous cyber capabilities. Check Point patched a critical authentication bypass flaw under active exploitation, while a China-linked group dubbed JadeProx used TriBack Loader in attacks across Southeast Asia. Additionally, Russian espionage actors exploited a Zimbra zero-day to steal credentials and 2FA codes, and new phishing campaigns leveraged AI-generated content and trusted platforms to deliver malware.
hacker-news ·1mo ago
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group exploited a zero-day vulnerability (CVE-2025-66376) in Zimbra's webmail client to conduct cyber espionage against Western government and commercial organizations. The vulnerability allowed attackers to steal emails, passwords, and 2FA codes through a zero-click exploit triggered by viewing a malicious email. The campaign, active since at least July 2025, used HTML smuggling and DNS-based exfiltration, targeting sectors including government, defense, and finance across NATO, Ukraine, CIS, and Africa.
hacker-news ·1mo ago
Russian hackers exploit Zimbra zero-click flaw for email theft
Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting a patched zero-click XSS vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite to steal email data, including credentials, 2FA tokens, and the Global Address List. The group targets organizations in the Defense Industrial Base, government, education, energy, and technology sectors, using both the vulnerability and adversary-in-the-middle phishing kits to bypass MFA and maintain persistent access. Stolen data is exfiltrated via DNS and HTTPS to attacker-controlled infrastructure using the 'Flowerbed' collection framework.
bleeping-computer ·1mo ago
Russian Global Webmail Espionage
Unit 42 has identified a persistent cyberespionage campaign, tracked as CL-STA-1114, attributed to a Russian threat actor. The campaign targets Zimbra webmail users in government, defense, transportation, and financial sectors across NATO, Ukraine, CIS, and African countries. Attackers exploit CVE-2025-66376 to deliver a zero-click JavaScript payload that exfiltrates credentials, email archives, and 2FA tokens. The activity highlights ongoing state-sponsored threats leveraging unpatched vulnerabilities in widely used collaboration platforms.
unit42 ·1mo ago