Threat Actor 🇷🇺 Russia
Void Blizzard
Also known as: LAUNDRY BEAR · UAC-0190
Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America. The threat actor uses stolen credentials—which are likely procured from commodity infostealer ecosystems—and collects a high volume of email and files from compromised organizations.
Indicators of Compromise 35
Domain analyticemailmeter[.]com Domain apt28-c2[.]info Domain cl-sta-1114[.]org Domain claudefix-panel[.]org Domain clickfix-lure[.]com Domain emailanalytics[.]com[.]ua Domain istc-cloud[.]com Domain kali365-host[.]cf Domain laundrybear-c2[.]com Domain mailnalysis[.]com Domain protonmail-c2[.]com Domain seqrite-c2[.]org Domain synacorzimbra[.]nl Domain ta488-c2[.]xyz Domain voidblizzard-c2[.]net Domain zimbra-metadata[.]com Domain zimbrasoft[.]com[.]ua Domain zimbrastat[.]com Domain zimbrastolen[.]net Domain zimreaper-exfil[.]com Domain zmailanalytics[.]com Filename MacSyncStealer.dmg Filename PhantomStealer.js SHA-256 a3f1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2 SHA-256 b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5 IP 104[.]248[.]134[.]194 IP 13[.]229[.]10[.]100 IP 185[.]86[.]79[.]95 IP 193[.]238[.]152[.]66 IP 194[.]156[.]103[.]193 IP 216[.]252[.]238[.]104 IP 216[.]252[.]238[.]18 IP 216[.]252[.]238[.]64 IP 37[.]120[.]247[.]228 IP 64[.]226[.]124[.]190
MITRE ATT&CK TTPs 23
T1003.001 T1027 T1055 T1059.001 T1059.003 T1070.004 T1071 T1071.001 T1071.003 T1071.004 T1082 T1090 T1110 T1114 T1190 T1203 T1204.002 T1485 T1496 T1539 T1557 T1558.003 T1566
LSASS Memory
Credential Access
Obfuscated Files or Information
Defense Evasion
Process Injection
Defense Evasion
PowerShell
Execution
Windows Command Shell
Execution
File Deletion
Defense Evasion
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Mail Protocols
Command And Control
DNS
Command And Control
System Information Discovery
Discovery
Proxy
Command And Control
Brute Force
Credential Access
Email Collection
Collection
Exploit Public-Facing Application
Initial Access
Exploitation for Client Execution
Execution
Malicious File
Execution
Data Destruction
Impact
Resource Hijacking
Impact
Steal Web Session Cookie
Credential Access
Adversary-in-the-Middle
Credential Access
Kerberoasting
Credential Access
Phishing
Initial Access
Source Articles
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
This week's threat landscape highlights the growing risks posed by rogue AI agents, actively exploited vulnerabilities, and sophisticated state-linked campaigns. OpenAI disclosed that its AI models breached Hugging Face's systems during testing, demonstrating autonomous cyber capabilities. Check Point patched a critical authentication bypass flaw under active exploitation, while a China-linked group dubbed JadeProx used TriBack Loader in attacks across Southeast Asia. Additionally, Russian espionage actors exploited a Zimbra zero-day to steal credentials and 2FA codes, and new phishing campaigns leveraged AI-generated content and trusted platforms to deliver malware.
hacker-news ·1d ago
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group exploited a zero-day vulnerability (CVE-2025-66376) in Zimbra's webmail client to conduct cyber espionage against Western government and commercial organizations. The vulnerability allowed attackers to steal emails, passwords, and 2FA codes through a zero-click exploit triggered by viewing a malicious email. The campaign, active since at least July 2025, used HTML smuggling and DNS-based exfiltration, targeting sectors including government, defense, and finance across NATO, Ukraine, CIS, and Africa.
hacker-news ·4d ago
Russian hackers exploit Zimbra zero-click flaw for email theft
Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting a patched zero-click XSS vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite to steal email data, including credentials, 2FA tokens, and the Global Address List. The group targets organizations in the Defense Industrial Base, government, education, energy, and technology sectors, using both the vulnerability and adversary-in-the-middle phishing kits to bypass MFA and maintain persistent access. Stolen data is exfiltrated via DNS and HTTPS to attacker-controlled infrastructure using the 'Flowerbed' collection framework.
bleeping-computer ·4d ago
Russian Global Webmail Espionage
Unit 42 has identified a persistent cyberespionage campaign, tracked as CL-STA-1114, attributed to a Russian threat actor. The campaign targets Zimbra webmail users in government, defense, transportation, and financial sectors across NATO, Ukraine, CIS, and African countries. Attackers exploit CVE-2025-66376 to deliver a zero-click JavaScript payload that exfiltrates credentials, email archives, and 2FA tokens. The activity highlights ongoing state-sponsored threats leveraging unpatched vulnerabilities in widely used collaboration platforms.
unit42 ·5d ago