Void Blizzard
MITRE G1014Also known as Laundry Bear, LAUNDRY BEAR, Void Blizzard, TA488, CL-STA-1114, UNK_PitStop
Reports
17
First seen
Dec 2, 2025
Last seen
Aug 7, 2026
Motivation
Espionage, Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×1×2
United States×2
Ukraine×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1190 Exploit Public-Facing Application ×13T1041 Exfiltration Over C2 Channel ×12T1566 Phishing ×12T1005 Data from Local System ×7T1059 Command and Scripting Interpreter ×5T1566.002 Phishing: Spearphishing Message ×5T1110 Brute Force ×4T1087 Account Discovery ×3T1047 Windows Management Instrumentation ×3T1555 Credentials from Password Stores ×3T1078 Valid Accounts ×3T1486 Data Encrypted for Impact ×3
Indicators
cve ×177domain ×42email ×21filename ×13ip_v4 ×11hash_sha1 ×10url ×10hash_sha256 ×5
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2025-66376 (exploited)CVE-2026-42897 (exploited)CVE-2026-48294CVE-2021-26858 (exploited)CVE-2023-2868 (exploited)CVE-2023-3519 (exploited)CVE-2021-43798 (exploited)CVE-2024-20353 (exploited)CVE-2024-20359 (exploited)CVE-2024-3400 (exploited)CVE-2024-42009 (exploited)CVE-2025-0282 (exploited)CVE-2025-20333 (exploited)CVE-2025-20362 (exploited)CVE-2025-5777 (exploited)CVE-2025-49113 (exploited)CVE-2025-61882 (exploited)CVE-2023-7102 (exploited)CVE-2026-10591CVE-2021-27065 (exploited)
Recent reports
Critical