#voidblizzard
Microsoft warns of Russian cyber group 'Void Blizzard' targeting critical infrastructure across Europe & North America. Stay vigilant. #CyberSecurity #VoidBlizzard #MicrosoftSecurity thedailytechfeed.com/russian-cybe...
May 27, 2025 at 5:33 PM
🫵 Hey CISO—still Googling “zero trust 101” while #VoidBlizzard live-streams your emails? ☁️🔥 Read the dossier before the GRU sends a thank-you fruit basket: blog.alphahunt.io/void-blizzar...
#AlphaHunt #CyberSecurity #CloudSecurity #Russia
Void Blizzard: Russian State-Backed Cloud Espionage, AitM Phishing, and LOTL Tactics Targeting NATO and Allies
Void Blizzard, a Russian state-sponsored APT attributed to the GRU and tracked as Laundry Bear by Dutch intelligence, has rapidly emerged as a major cyber espionage threat since April 2024. The group…
blog.alphahunt.io
July 12, 2025 at 3:17 PM
Hey manager, reading cloud intel isn’t on your to-do? Good thing #VoidBlizzard crashed your console and your sense of urgency.

🎯 Dive into the mess before the #GRU throws your creds on the barbecue 👇

blog.alphahunt.io/void-blizzar...

#AlphaHunt #CyberSecurity #CloudSecurity
Void Blizzard: Russian State-Backed Cloud Espionage, AitM Phishing, and LOTL Tactics Targeting NATO and Allies
Void Blizzard, a Russian state-sponsored APT attributed to the GRU and tracked as Laundry Bear by Dutch intelligence, has rapidly emerged as a major cyber espionage threat since April 2024. The group…
blog.alphahunt.io
June 22, 2025 at 3:28 PM
August 3, 2026 at 3:43 PM
July 31, 2026 at 1:14 AM
Russian hackers are exploiting a new Exchange OWA XSS flaw in half-click email attacks, deploying OWAReaper for long-term mailbox access across U.S. and European government and industry targets. #Russia #Exchange #OWAReaper
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Laundry Bear, also tracked as Void Blizzard and TA488, is using the CVE-2026-42897 Outlook Web Access XSS flaw in half-click email attacks to deliver the OWAReaper backdoor. The campaign targets government and industry organizations across the U.S. and Europe and uses advanced persistence, credential theft, and multi-channel command-and-control to maintain long-term mailbox access. #LaundryBear #VoidBlizzard #TA488 #CVE-2026-42897 #OWAReaper #MicrosoftExchange #OutlookWebAccess
www.hendryadrian.com
July 30, 2026 at 1:45 AM
Russian state-backed Laundry Bear is exploiting Zimbra CVE-2025-66376 with malicious HTML emails that auto-run JavaScript, stealing mailboxes and bypassing MFA across government, defense, and other sectors. #Russia #Zimbra #LaundryBear
Russian hackers exploit Zimbra zero-click flaw for email theft
CISA says the Russian state-sponsored group Laundry Bear, also known as Void Blizzard, is targeting Zimbra Collaboration servers with phishing and the now-patched CVE-2025-66376 XSS flaw to steal email data and bypass MFA. The campaign has hit organizations across government, defense, education, energy, media, and NGOs, while exfiltrating stolen information through the group's Flowerbed framework and AiTM phishing kits. #LaundryBear #VoidBlizzard #Zimbra #CVE202566376 #Flowerbed
www.hendryadrian.com
July 24, 2026 at 1:15 AM
Russian national Denis Nikolayevich Obrezko was charged in a Void Blizzard espionage case. Prosecutors say he helped buy infrastructure used to target U.S. and European organizations and hide activity. #Russia #VoidBlizzard #LaundryBear
Russian national charged in connection with Void Blizzard espionage campaign
Federal prosecutors have charged Russian national Denis Nikolayevich Obrezko with conspiracy to commit unauthorized computer access in connection with a cyber-espionage campaign linked to Void Blizzard, also known as Laundry Bear. Investigators say the group targeted U.S. and European organizations, using stolen session tokens, proxy services, and typosquatted Microsoft domains to steal data and conceal its activity. #VoidBlizzard #LaundryBear #DenisNikolayevichObrezko #MicrosoftEntraID
www.hendryadrian.com
June 11, 2026 at 6:45 PM
~Microsoft~
This actor targets critical sectors (NATO/UA) with stolen creds & AitM phishing.
-
IOCs: micsrosoftonline. com, ebsumrnit. eu, outlook-office. micsrosoftonline. com
-
#Espionage #ThreatIntel #VoidBlizzard
Void Blizzard (LAUNDRY BEAR): RU Espionage
www.microsoft.com
May 27, 2025 at 12:06 PM
🚨 New blog post 🚨

Hunting Laundry Bear: Infrastructure Analysis Guide and Findings

How to enrich previous reporting with Validin to find dozens of indicators not previously reported.

#LaundryBear #VoidBlizzard #APT

www.validin.com/blog/laundry...
Hunting Laundry Bear: Infrastructure Analysis Guide and Findings | Validin
Hunting Laundry Bear: Infrastructure Analysis Guide and Findings
www.validin.com
July 25, 2025 at 12:13 PM