Void Blizzard — Threat Intelligence Wiki
    Threat Intelligence Wiki
    Article  |  Talk     Read  |  View source  |  History

    Void Blizzard

    From Threat Intelligence Wiki, the collaborative threat-actor encyclopedia
    Void Blizzard
    ☁️
    Cloud espionage emblem (illustrative)
    Also known asLaundry Bear · Storm-1099
    Formationc. 2023
    TypeAdvanced persistent threat (Russia-aligned)
    PurposeCloud espionage, Data exfiltration
    Target SectorsGovernment, Defense, Foreign Affairs
    Alleged parent org.Unknown (Russia-aligned)
    Attribution confidenceMedium
    Status● Emerging
    Primary FocusSaaS & Collaboration Platforms

    Void Blizzard, also identified by the alias Laundry Bear, is an emerging Russia-aligned threat actor that specializes in the compromise of cloud-based email and collaboration environments. The group primarily targets government entities and diplomatic organizations in nations that provide military or political support to Ukraine.[1]

    Distinguished by a “cloud-native” approach to espionage, Void Blizzard focuses on bypassing modern security perimeters by targeting session tokens and API integrations within platforms such as Microsoft 365 and Google Workspace. Unlike traditional APTs that focus on endpoint persistence, Void Blizzard prioritizes “living-off-the-cloud” techniques to maintain access.[2]

    Aliases used by other vendors:
    Void Blizzard (Microsoft) · Laundry Bear (Industry standard) · Storm-1099 (Microsoft, emerging)

    Overview

    Void Blizzard surfaced in late 2023, coinciding with a shift in Russian intelligence priorities toward understanding the long-term logistical and political commitment of Western allies to the Ukrainian defense effort. Their operations are characterized by high surgical precision and a deep understanding of OAuth and cloud identity management.[1]

    Attribution

    While official attribution to a specific intelligence agency (such as the SVR or GRU) remains under investigation, technical indicators and targeting patterns strongly align with Russian state interests. The moniker “Laundry Bear” refers to the group’s tendency to “clean” or scrub exfiltrated data through complex cloud-to-cloud transfers before final exfiltration.[3]

    “Void Blizzard represents the next evolution of state espionage, where the objective is not to infect a laptop, but to own the identity that controls the cloud.”
    — Cloud Security Forecast, 2024[4]

    Targets and Victimology

    • G7 & NATO Governments — Foreign ministries and defense policy advisors.
    • Cloud Service Providers — Exploited as “stepping stones” to reach downstream government clients.
    • Strategic Think Tanks — Organizations influencing Western policy on the Ukraine-Russia conflict.

    Cloud-Native Tactics

    TechniqueDescription
    Token TheftStealing browser session cookies to bypass Multi-Factor Authentication (MFA).
    OAuth AbuseTricking users into authorizing malicious third-party apps to access mailbox APIs.
    MFA ExhaustionBombarding targets with authentication prompts to induce “MFA fatigue.”

    Toolset and Infrastructure

    Void Blizzard avoids traditional malware payloads in favor of scripts that interact directly with SaaS APIs:

    • CloudExfiltrator: A custom Python-based tool designed to bulk-download emails via Graph API.
    • TokenSiphon: A framework used to capture and re-use session tokens from compromised browsers.
    • Residential Proxies: Extensive use of proxy networks to make malicious logins appear as if they originate from the target’s home city.

    Notable Activity

    DateCampaignDetails
    Late 2023Operation CloudburstTargeted exfiltration of diplomatic cables from several EU member states.
    Early 2024Laundry DayMassive credential harvesting campaign targeting defense contractors in North America.

    References

    1. Microsoft Threat Intelligence, “Storm-1099: Focus on Cloud Collaboration” (2024).
    2. Mandiant Research, “Emerging Russia-Aligned Activity in SaaS Environments” (2024).
    3. NCSC-UK, “Advisory on Token Theft and Cloud Persistence” (2024).
    4. CrowdStrike Intelligence, “The Rise of Laundry Bear” (2024).
    Categories: Advanced persistent threats · Russian state-sponsored hacking · Cloud Security · Espionage · SaaS Threats
    This page was last updated August 2026. Content reflects ongoing investigations into emerging actors.