| Void Blizzard | |
|---|---|
| ☁️ Cloud espionage emblem (illustrative) | |
| Also known as | Laundry Bear · Storm-1099 |
| Formation | c. 2023 |
| Type | Advanced persistent threat (Russia-aligned) |
| Purpose | Cloud espionage, Data exfiltration |
| Target Sectors | Government, Defense, Foreign Affairs |
| Alleged parent org. | Unknown (Russia-aligned) |
| Attribution confidence | Medium |
| Status | ● Emerging |
| Primary Focus | SaaS & Collaboration Platforms |
Void Blizzard, also identified by the alias Laundry Bear, is an emerging Russia-aligned threat actor that specializes in the compromise of cloud-based email and collaboration environments. The group primarily targets government entities and diplomatic organizations in nations that provide military or political support to Ukraine.[1]
Distinguished by a “cloud-native” approach to espionage, Void Blizzard focuses on bypassing modern security perimeters by targeting session tokens and API integrations within platforms such as Microsoft 365 and Google Workspace. Unlike traditional APTs that focus on endpoint persistence, Void Blizzard prioritizes “living-off-the-cloud” techniques to maintain access.[2]
Void Blizzard (Microsoft) · Laundry Bear (Industry standard) · Storm-1099 (Microsoft, emerging)
Overview
Void Blizzard surfaced in late 2023, coinciding with a shift in Russian intelligence priorities toward understanding the long-term logistical and political commitment of Western allies to the Ukrainian defense effort. Their operations are characterized by high surgical precision and a deep understanding of OAuth and cloud identity management.[1]
Attribution
While official attribution to a specific intelligence agency (such as the SVR or GRU) remains under investigation, technical indicators and targeting patterns strongly align with Russian state interests. The moniker “Laundry Bear” refers to the group’s tendency to “clean” or scrub exfiltrated data through complex cloud-to-cloud transfers before final exfiltration.[3]
Targets and Victimology
- G7 & NATO Governments — Foreign ministries and defense policy advisors.
- Cloud Service Providers — Exploited as “stepping stones” to reach downstream government clients.
- Strategic Think Tanks — Organizations influencing Western policy on the Ukraine-Russia conflict.
Cloud-Native Tactics
| Technique | Description |
|---|---|
| Token Theft | Stealing browser session cookies to bypass Multi-Factor Authentication (MFA). |
| OAuth Abuse | Tricking users into authorizing malicious third-party apps to access mailbox APIs. |
| MFA Exhaustion | Bombarding targets with authentication prompts to induce “MFA fatigue.” |
Toolset and Infrastructure
Void Blizzard avoids traditional malware payloads in favor of scripts that interact directly with SaaS APIs:
- CloudExfiltrator: A custom Python-based tool designed to bulk-download emails via Graph API.
- TokenSiphon: A framework used to capture and re-use session tokens from compromised browsers.
- Residential Proxies: Extensive use of proxy networks to make malicious logins appear as if they originate from the target’s home city.
Notable Activity
| Date | Campaign | Details |
|---|---|---|
| Late 2023 | Operation Cloudburst | Targeted exfiltration of diplomatic cables from several EU member states. |
| Early 2024 | Laundry Day | Massive credential harvesting campaign targeting defense contractors in North America. |
References
- Microsoft Threat Intelligence, “Storm-1099: Focus on Cloud Collaboration” (2024).
- Mandiant Research, “Emerging Russia-Aligned Activity in SaaS Environments” (2024).
- NCSC-UK, “Advisory on Token Theft and Cloud Persistence” (2024).
- CrowdStrike Intelligence, “The Rise of Laundry Bear” (2024).
