| Cadet Blizzard | |
|---|---|
| ❄️ Winter offensive emblem (illustrative) | |
| Also known as | Ember Bear · UAC-0056 · Bleeding Bear · TA471 · SaintBear |
| Formation | c. 2020 |
| Type | Advanced persistent threat (state-sponsored) |
| Purpose | Destructive operations, Sabotage, Espionage |
| Target Sectors | Government, Emergency Services, IT Providers |
| Alleged parent org. | GRU (Unit 29155) |
| Attribution confidence | High |
| Status | ● Active |
| Notable tools | WhisperGate, SaintBot, OutSteel, GraphSteel |
Cadet Blizzard, also known as Ember Bear and UAC-0056, is a Russian state-sponsored threat actor operated by the GRU (Main Intelligence Directorate). The group emerged as a distinct entity in 2020 and gained global notoriety for its destructive cyber-attacks against Ukraine immediately preceding the 2022 full-scale invasion.[1]
The group is characterized by its use of “pseudo-ransomware”—malware designed to look like financial extortion but which is actually a destructive wiper. Cadet Blizzard’s primary mandate appears to be the disruption of government services and the demoralization of the target population through information operations.[2]
Cadet Blizzard (Microsoft) · Ember Bear (CrowdStrike) · UAC-0056 (CERT-UA) · Bleeding Bear (SentinelOne) · TA471 (Proofpoint)
Overview
While often compared to the GRU’s Sandworm (APT44), Cadet Blizzard operates with distinct infrastructure and toolsets. Their operations are frequently timed to coincide with major geopolitical shifts or military escalations, serving as a digital vanguard for physical operations.[1]
Attribution
In 2024, the U.S. and its allies (including the UK, Australia, and Canada) formally attributed Cadet Blizzard’s activities to GRU Unit 29155. This unit is traditionally known for kinetic “wetwork,” including sabotage and assassination attempts in Europe, indicating a convergence of cyber and physical GRU sabotage mandates.[3]
Targets and Victimology
- Ukrainian Government — Ministries of Foreign Affairs, Agriculture, and Education.
- IT Managed Service Providers (MSPs) — Targeted for “supply chain” style access into government networks.
- Emergency Services — Disruption of critical response systems during conflict.
The WhisperGate Campaign
In January 2022, Cadet Blizzard deployed WhisperGate against dozens of Ukrainian government systems. The attack consisted of three stages:
- Master Boot Record (MBR) Wiper: Overwriting the MBR to make the system unbootable.
- Extortion Note: Displaying a fake ransom demand for $10,000 in Bitcoin.
- File Corruptor: A second payload that specifically targeted and destroyed files with certain extensions.
Malware Toolset
| Name | Function |
|---|---|
| WhisperGate | Two-stage destructive wiper disguised as ransomware. |
| SaintBot | A downloader used to drop secondary payloads and maintain persistence. |
| OutSteel | A document-stealing tool used to exfiltrate sensitive PDF and Word files. |
| GraphSteel | An info-stealer that focuses on credential harvesting and system metadata. |
Tactics and Procedures
| Tactic | Technique | Notes |
|---|---|---|
| Persistence | Web Shells | Deploying shells on compromised servers to ensure long-term access. |
| Exfiltration | Discord/Telegram | Using legitimate messaging APIs to exfiltrate stolen data and evade detection. |
| Impact | Data Destruction | Wiping disks and deleting backups to maximize recovery time. |
References
- Microsoft, “Cadet Blizzard: Emergence of a New GRU Actor” (2023).
- CERT-UA, “UAC-0056: Destructive Cyberattacks against Ukraine” (2022).
- U.S. Department of State, “Reward for Information on GRU Unit 29155” (2024).
- SentinelOne, “Bleeding Bear: A Closer Look at WhisperGate” (2022).
