Void Blizzard is a Russia-aligned cyberespionage group known for mass email data collection using stolen credentials.
Analyst brief
Void Blizzard is a cyberespionage group aligned with Russian government interests. It primarily targets government, defense, transportation, media, NGO, and healthcare sectors in Europe and North America. The main TTPs involve using stolen credentials likely sourced from commodity infostealer ecosystems and collecting high volumes of email and files from compromised organizations. Defenders should focus on monitoring for credential compromise and anomalies indicative of mass data exfiltration, especially from email systems.
Void Blizzard
LAUNDRY BEARUAC-0190TA488
unknown
Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America. The threat actor uses stolen credentials—which are likely procured from commodity infostealer ecosystems—and collects a high volume of email and files from compromised organizations.
Void Blizzard primarily targets government, defense, transportation, media, NGO, and healthcare sectors in Europe and North America.
What are the main TTPs employed by Void Blizzard in compromised organizations?+
The group uses stolen credentials likely sourced from commodity infostealer ecosystems and collects a high volume of email and files from compromised organizations.