Cadet Blizzard — Threat Intelligence Wiki
    Threat Intelligence Wiki
    Article  |  Talk     Read  |  View source  |  History

    Cadet Blizzard

    From Threat Intelligence Wiki, the collaborative threat-actor encyclopedia
    Cadet Blizzard
    ❄️
    Winter offensive emblem (illustrative)
    Also known asEmber Bear · UAC-0056 · Bleeding Bear · TA471 · SaintBear
    Formationc. 2020
    TypeAdvanced persistent threat (state-sponsored)
    PurposeDestructive operations, Sabotage, Espionage
    Target SectorsGovernment, Emergency Services, IT Providers
    Alleged parent org.GRU (Unit 29155)
    Attribution confidenceHigh
    Status● Active
    Notable toolsWhisperGate, SaintBot, OutSteel, GraphSteel

    Cadet Blizzard, also known as Ember Bear and UAC-0056, is a Russian state-sponsored threat actor operated by the GRU (Main Intelligence Directorate). The group emerged as a distinct entity in 2020 and gained global notoriety for its destructive cyber-attacks against Ukraine immediately preceding the 2022 full-scale invasion.[1]

    The group is characterized by its use of “pseudo-ransomware”—malware designed to look like financial extortion but which is actually a destructive wiper. Cadet Blizzard’s primary mandate appears to be the disruption of government services and the demoralization of the target population through information operations.[2]

    Aliases used by other vendors:
    Cadet Blizzard (Microsoft) · Ember Bear (CrowdStrike) · UAC-0056 (CERT-UA) · Bleeding Bear (SentinelOne) · TA471 (Proofpoint)

    Overview

    While often compared to the GRU’s Sandworm (APT44), Cadet Blizzard operates with distinct infrastructure and toolsets. Their operations are frequently timed to coincide with major geopolitical shifts or military escalations, serving as a digital vanguard for physical operations.[1]

    Attribution

    In 2024, the U.S. and its allies (including the UK, Australia, and Canada) formally attributed Cadet Blizzard’s activities to GRU Unit 29155. This unit is traditionally known for kinetic “wetwork,” including sabotage and assassination attempts in Europe, indicating a convergence of cyber and physical GRU sabotage mandates.[3]

    “Cadet Blizzard’s operations are not about intelligence gathering alone; they are about causing visible, psychological damage to the functions of a sovereign state.”
    — Microsoft Threat Intelligence Report, 2023[4]

    Targets and Victimology

    • Ukrainian Government — Ministries of Foreign Affairs, Agriculture, and Education.
    • IT Managed Service Providers (MSPs) — Targeted for “supply chain” style access into government networks.
    • Emergency Services — Disruption of critical response systems during conflict.

    The WhisperGate Campaign

    In January 2022, Cadet Blizzard deployed WhisperGate against dozens of Ukrainian government systems. The attack consisted of three stages:

    1. Master Boot Record (MBR) Wiper: Overwriting the MBR to make the system unbootable.
    2. Extortion Note: Displaying a fake ransom demand for $10,000 in Bitcoin.
    3. File Corruptor: A second payload that specifically targeted and destroyed files with certain extensions.

    Malware Toolset

    NameFunction
    WhisperGateTwo-stage destructive wiper disguised as ransomware.
    SaintBotA downloader used to drop secondary payloads and maintain persistence.
    OutSteelA document-stealing tool used to exfiltrate sensitive PDF and Word files.
    GraphSteelAn info-stealer that focuses on credential harvesting and system metadata.

    Tactics and Procedures

    TacticTechniqueNotes
    PersistenceWeb ShellsDeploying shells on compromised servers to ensure long-term access.
    ExfiltrationDiscord/TelegramUsing legitimate messaging APIs to exfiltrate stolen data and evade detection.
    ImpactData DestructionWiping disks and deleting backups to maximize recovery time.

    References

    1. Microsoft, “Cadet Blizzard: Emergence of a New GRU Actor” (2023).
    2. CERT-UA, “UAC-0056: Destructive Cyberattacks against Ukraine” (2022).
    3. U.S. Department of State, “Reward for Information on GRU Unit 29155” (2024).
    4. SentinelOne, “Bleeding Bear: A Closer Look at WhisperGate” (2022).
    Categories: Advanced persistent threats · Russian state-sponsored hacking · GRU · Cyberwarfare · Wipers
    This page was last updated August 2026. Content reflects public forensic analysis.