Skip to main content
Mallory
Russia6 malware families

Void Blizzard

Also known asLaundry Bearuac_0190Void Blizzard

Void Blizzard is a Russian state-sponsored espionage threat actor, also tracked as Laundry Bear and UAC-0190. The group has been described as active since at least April 2024 and is linked in the reporting to Russian government objectives. Reported targeting includes Ukraine, NATO-affiliated organizations, and organizations in Europe and North America, with specific focus on government, defense, transportation, media, NGOs, healthcare, and other entities important to Russian intelligence requirements. Multiple reports state the group targeted Ukrainian government institutions, members of Ukraine’s armed forces and defense forces, and more than 20 NATO-affiliated organizations. Observed tradecraft includes social engineering via Signal, WhatsApp, Telegram, phone calls, video chats, and other messaging platforms; use of legitimate accounts, Ukrainian mobile numbers, and Ukrainian-language interaction to build trust; charity-themed lures; fake charity websites; password-protected archives; deceptive double extensions such as .docx.pif and .pdf.exe; QR codes embedded in PDF attachments; and adversary-in-the-middle phishing using Evilginx. Reporting also states Void Blizzard used stolen credentials and authentication tokens, sometimes alongside MFA fatigue techniques, and in some cases accessed Microsoft Teams via the web client. Post-compromise activity includes email and file theft, long-term espionage, and cloud identity discovery. Microsoft-attributed reporting says the group used stolen credentials to collect emails and files. Unit 42 reporting states Void Blizzard repurposed AzureHound for post-compromise discovery in Microsoft Entra ID environments, including enumeration of users, devices, service principals, roles, app role assignments, key vault policies, storage accounts, and cloud services. Malware and tooling linked in the content include PLUGGYAPE and DRILLAPP. CERT-UA attributed with medium confidence a 2025 campaign against Ukraine’s Defense Forces to Void Blizzard/Laundry Bear/UAC-0190, delivering the Python backdoor PLUGGYAPE via messaging-app social engineering and fake charity sites. PLUGGYAPE supports remote command execution, persistence via Windows Run registry changes, host profiling, and C2 over WebSocket or MQTT, with later variants retrieving base64-encoded C2 details from paste services such as rentry.co and pastebin.com and adding obfuscation and anti-analysis or VM checks. Separate 2026 reporting linked with low confidence a DRILLAPP backdoor campaign targeting Ukrainian organizations to Laundry Bear/Void Blizzard based on overlaps with earlier tradecraft, including charity-themed lures and use of public text-sharing services. DRILLAPP abused Microsoft Edge headless and debugging features to access the file system and capture microphone, camera, and screen data. The content also references Dutch intelligence tracking the group as Laundry Bear and Microsoft tracking it as Void Blizzard, and states the group was linked in reporting to a 2024 breach of Dutch police systems.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Military

Where they target

Geographies tied to known operations.

  • 🇺🇦 Ukraine
MITRE ATT&CK

Tradecraft

41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics55 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1589
Gather Victim Identity Information
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.001
Domains
TA0001
Initial Access
4 techniques
T1078×2
Valid Accounts
T1133
External Remote Services
T1190
Exploit Public-Facing Application
T1566×3
Phishing
T1566.001×3
Spearphishing Attachment
T1566.002×2
Spearphishing Link
T1566.003
Spearphishing via Service
TA0002
Execution
2 techniques
T1059×2
Command and Scripting Interpreter
T1059.006
Python
T1059.007
JavaScript
T1204
User Execution
T1204.002
Malicious File
TA0003
Persistence
3 techniques
T1078×2
Valid Accounts
T1133
External Remote Services
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
2 techniques
T1078×2
Valid Accounts
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
3 techniques
T1036×2
Masquerading
T1078×2
Valid Accounts
T1497
Virtualization/Sandbox Evasion
T1497.001
System Checks
TA0006
Credential Access
5 techniques
T1110
Brute Force
T1110.003
Password Spraying
T1539×2
Steal Web Session Cookie
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
T1557×2
Adversary-in-the-Middle
T1621
Multi-Factor Authentication Request Generation
TA0007
Discovery
6 techniques
T1069
Permission Groups Discovery
T1082×2
System Information Discovery
T1083
File and Directory Discovery
T1087
Account Discovery
T1087.004
Cloud Account
T1497
Virtualization/Sandbox Evasion
T1497.001
System Checks
T1526×2
Cloud Service Discovery
TA0009
Collection
8 techniques
T1005
Data from Local System
T1113
Screen Capture
T1114
Email Collection
T1119
Automated Collection
T1123
Audio Capture
T1125
Video Capture
T1530
Data from Cloud Storage
T1557×2
Adversary-in-the-Middle
TA0011
Command and Control
4 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1102
Web Service
T1105×2
Ingress Tool Transfer
T1568
Dynamic Resolution
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
ARSENAL

Associated malware families

6 malware families attributed to this actor across reporting.

1 additional family tracked in Mallory.

IOCS

Observables

142 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping41

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal6

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables142

Domains, IPs, and hashes tied to this actor, refreshed continuously.