Microsoft has uncovered a Russia-affiliated threat actor named Void Blizzard (also known as Laundry Bear) conducting widespread cloud-based espionage operations since April 2024. The group primarily targets organizations aligned with Russian government interests across Europe and North America.
## Target Sectors and Methodology
The hackers focus on government agencies, defense contractors, transportation companies, media outlets, NGOs, and healthcare organizations—with a particular emphasis on NATO member states and Ukraine. Their goal appears to be gathering intelligence that advances Russian strategic objectives.
Void Blizzard employs relatively unsophisticated but effective techniques:
– Purchasing stolen credentials from dark web marketplaces
– Conducting password spraying attacks
– Using the AzureHound tool to map organizational structures
– Deploying spear-phishing emails with fake event invitations
## Recent Attack Evolution
In October 2024, the group successfully compromised user accounts at a Ukrainian aviation organization previously targeted by another Russian intelligence group in 2022. More recently, they’ve shifted to more direct password theft methods, including:
– Creating adversary-in-the-middle phishing pages
– Using typosquatted domains mimicking Microsoft Entra authentication portals
– Embedding malicious QR codes in PDF attachments
– Leveraging the open-source Evilginx phishing kit
## Post-Compromise Activities
Once inside target networks, Void Blizzard:
– Steals emails and files in bulk using automation
– Abuses Exchange Online and Microsoft Graph APIs
– Accesses Microsoft Teams conversations
– Collects intelligence on organizations of interest to Russia
## Dutch Police Breach Connection
The Netherlands Defence Intelligence and Security Service has linked Void Blizzard to a September 2024 breach of a Dutch police employee account. The attack used a pass-the-cookie technique to bypass authentication requirements, resulting in the theft of police contact information.
According to MIVD director Vice Admiral Peter Reesink, “Laundry Bear is looking for information about the purchase and production of military equipment by Western governments and Western supplies of weapons to Ukraine.”
