Void Blizzard

☆ pin
MITRE G1014Also known as Laundry Bear, LAUNDRY BEAR, Void Blizzard, TA488, CL-STA-1114, UNK_PitStop
Reports
17
First seen
Dec 2, 2025
Last seen
Aug 7, 2026
Motivation
Espionage, Financial

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×1
×2
United States×2
Ukraine×1

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1190 Exploit Public-Facing Application ×13T1041 Exfiltration Over C2 Channel ×12T1566 Phishing ×12T1005 Data from Local System ×7T1059 Command and Scripting Interpreter ×5T1566.002 Phishing: Spearphishing Message ×5T1110 Brute Force ×4T1087 Account Discovery ×3T1047 Windows Management Instrumentation ×3T1555 Credentials from Password Stores ×3T1078 Valid Accounts ×3T1486 Data Encrypted for Impact ×3

Indicators

cve ×177domain ×42email ×21filename ×13ip_v4 ×11hash_sha1 ×10url ×10hash_sha256 ×5

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

Critical

Russian State-Sponsored Group Laundry Bear Exploits Zimbra Flaw to Steal Emails Without User Interaction

Proofpoint Threat Insight
Critical

Weekly Cybersecurity Recap: AI Model Breaches, Water-System Attacks, Ransomware, and Critical Vulnerabilities

The Hacker News
High

Cyber Brief July 2026 – EU Threat Intelligence Summary

CERT-EU Threat Intel
Critical

Russian Hackers Exploit Microsoft OWA Flaw to Maintain Persistent Mailbox Access

The Hacker News
Critical

Russian Laundry Bear exploits Exchange OWA zero-day for persistent mailbox access

Bleeping Computer
Critical

Laundry Bear exploits Microsoft OWA vulnerability with sophisticated OWAReaper implant

The Record (Recorded Future News)
Critical

Weekly Threat Recap: AI Breach at Hugging Face, Check Point Exploit, Ransomware Campaigns, and Emerging Attack Vectors

The Hacker News
High

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Hacker News
High

Russian espionage group exploiting Zimbra zero-day to steal sensitive data from Western governments and organizations

CyberScoop
Critical

Russia-linked Laundry Bear targets Zimbra webmail across NATO and Ukraine

The Record (Recorded Future News)
Critical

Russian Laundry Bear exploits Zimbra zero-click XSS flaw to steal emails and credentials

Bleeping Computer
Critical

Russian APT Laundry Bear Exploits Zimbra Zero-Day for Espionage Against Western Governments

Proofpoint Threat Insight
Critical

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Zimbra Collaboration Suite

CISA Advisories
High

Russian national charged in Void Blizzard espionage campaign

CyberScoop
High

Russian national linked to Void Blizzard charged in U.S. cyberespionage campaign

The Record (Recorded Future News)
High

2025 Cloud Threat Hunting and Defense Landscape

Recorded Future Insikt
High

Cyber Brief November 2025: Operation Endgame, Sandworm Wipers, China AI Espionage

CERT-EU Threat Intel

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.