{
  "schema_version": "1.0.0",
  "generated_at": "2026-08-21T20:36:12.530Z",
  "publisher": "HECAVEX",
  "licence": "CC-BY-4.0",
  "licence_url": "https://apt.hecavex.com/licence/",
  "methodology": "https://apt.hecavex.com/about/methodology/",
  "notice": "Curated public research records. Not a live IOC feed or exhaustive actor directory.",
  "actors": [
    {
      "id": "apt28",
      "name": "APT28",
      "slug": "apt28",
      "summary": "A Russian military intelligence intrusion set associated with GRU Unit 26165 and persistent espionage against governments, defence, logistics, technology, identity systems and organisations supporting Ukraine.",
      "draft": false,
      "actor_types": [
        "state-sponsored"
      ],
      "status": "active",
      "suspected_origins": [
        "Russia"
      ],
      "motivations": [
        "espionage",
        "credential-access",
        "data-theft"
      ],
      "active_since": "2004",
      "last_observed": "2026",
      "confidence": "high",
      "last_reviewed": "2026-08-09T00:00:00.000Z",
      "authors": [
        "deividas-lis"
      ],
      "mission": "Collect strategic and military intelligence in support of Russian government foreign-policy and operational objectives, with recurring emphasis on identity, email, defence, logistics and Ukraine-related networks.",
      "current_assessment": "APT28 remains an active, adaptive espionage actor. Its recent operations combine rapid client-side exploitation, long-term mailbox access and compromised edge infrastructure that can expose authentication flows before traffic reaches an organisation's managed boundary.",
      "aliases": [
        {
          "name": "Fancy Bear",
          "source": "Industry and government reporting",
          "relationship": "common-alias",
          "confidence": "high",
          "scope": "Broad public designation for activity associated with APT28.",
          "first_seen": "2014",
          "last_seen": "2026",
          "notes": "Widely used, but individual publishers may apply different cluster boundaries."
        },
        {
          "name": "Forest Blizzard",
          "source": "Microsoft",
          "relationship": "vendor-tracking-cluster",
          "confidence": "high",
          "scope": "Microsoft cluster overlapping APT28 and Unit 26165 activity.",
          "first_seen": "2023 naming",
          "last_seen": "2026",
          "notes": "Previously tracked by Microsoft as STRONTIUM."
        },
        {
          "name": "Sednit",
          "source": "ESET",
          "relationship": "vendor-tracking-cluster",
          "confidence": "high",
          "scope": "ESET tracking designation used for overlapping activity and tooling.",
          "first_seen": "historical",
          "last_seen": "2025",
          "notes": "Operation RoundPress is linked to Sednit with medium, not high, confidence."
        },
        {
          "name": "Sofacy",
          "source": "Industry reporting",
          "relationship": "historical-designation",
          "confidence": "high",
          "scope": "Historical designation used for both actor activity and associated malware in some reporting.",
          "first_seen": "historical",
          "last_seen": "2026",
          "notes": "Ambiguous usage requires source context."
        },
        {
          "name": "STRONTIUM",
          "source": "Microsoft",
          "relationship": "historical-designation",
          "confidence": "high",
          "scope": "Former Microsoft tracking name now replaced by Forest Blizzard.",
          "first_seen": "historical",
          "last_seen": "2023",
          "notes": "Retained for searching older reporting."
        },
        {
          "name": "Pawn Storm",
          "source": "Trend Micro",
          "relationship": "vendor-tracking-cluster",
          "confidence": "high",
          "scope": "Vendor cluster with broad overlap to APT28.",
          "first_seen": "historical",
          "last_seen": "2026",
          "notes": "Do not assume exact campaign boundaries match other vendors."
        },
        {
          "name": "FROZENLAKE",
          "source": "Google Threat Intelligence Group",
          "relationship": "vendor-tracking-cluster",
          "confidence": "high",
          "scope": "Google tracking designation overlapping APT28.",
          "first_seen": "historical",
          "last_seen": "2025",
          "notes": "Used by GTIG in reporting on PROMPTSTEAL."
        },
        {
          "name": "BlueDelta",
          "source": "Recorded Future",
          "relationship": "vendor-tracking-cluster",
          "confidence": "high",
          "scope": "Vendor designation referenced in joint government reporting.",
          "first_seen": "historical",
          "last_seen": "2025",
          "notes": "Recorded as an overlapping industry cluster."
        },
        {
          "name": "GruesomeLarch",
          "source": "Volexity",
          "relationship": "vendor-tracking-cluster",
          "confidence": "high",
          "scope": "Volexity designation used for the Nearest Neighbor investigation.",
          "first_seen": "2022 activity",
          "last_seen": "2024",
          "notes": "High-confidence attribution within Volexity's investigated incident."
        }
      ],
      "parent_entities": [
        {
          "name": "GRU 85th Main Special Service Centre, Military Unit 26165",
          "entity_type": "Russian military intelligence unit",
          "relationship": "attributed operator",
          "confidence": "high",
          "source": "ncsc-apt28-dns-2026",
          "notes": "The NCSC assesses APT28 is almost certainly the GRU 85th GTsSS, Military Unit 26165."
        }
      ],
      "subclusters": [
        {
          "name": "Storm-2754",
          "source": "Microsoft",
          "relationship": "subgroup",
          "confidence": "high",
          "notes": "Microsoft describes Storm-2754 as a component or sub-group associated with Forest Blizzard's router and DNS activity, not as a synonym for all APT28 operations."
        }
      ],
      "attribution": [
        {
          "claim": "The NCSC assesses that APT28 is almost certainly the GRU 85th Main Special Service Centre, Military Unit 26165.",
          "attributed_entity": "GRU 85th GTsSS, Military Unit 26165",
          "source": "ncsc-apt28-dns-2026",
          "source_type": "government",
          "published_at": "2026-04-07T00:00:00.000Z",
          "confidence": "high",
          "status": "assessed",
          "notes": "This is the current UK government assessment and the primary identity statement used by APT Notes."
        },
        {
          "claim": "A joint multinational advisory attributes the western logistics and technology campaign to GRU Unit 26165.",
          "attributed_entity": "GRU Unit 26165",
          "source": "cisa-aa25-141a",
          "source_type": "government",
          "published_at": "2025-05-21T00:00:00.000Z",
          "confidence": "high",
          "status": "reported",
          "notes": "The advisory cautions that industry tracking names may not correlate one-to-one with the government's activity grouping."
        },
        {
          "claim": "The United States disrupted a router botnet used by Unit 26165 to conceal credential-harvesting operations.",
          "attributed_entity": "GRU Unit 26165",
          "source": "doj-soho-botnet-2024",
          "source_type": "legal",
          "published_at": "2024-02-15T00:00:00.000Z",
          "confidence": "high",
          "status": "confirmed",
          "notes": "The legal action establishes the government's attribution for the disrupted infrastructure, not every campaign using compromised routers."
        },
        {
          "claim": "ThreatLabz attributes Operation Neusploit to APT28 with high confidence based on victimology and overlapping tools, infrastructure and techniques.",
          "attributed_entity": "APT28",
          "source": "zscaler-operation-neusploit",
          "source_type": "vendor-research",
          "published_at": "2026-02-02T00:00:00.000Z",
          "confidence": "high",
          "status": "assessed",
          "notes": "Vendor assessment for this campaign; it is not presented as a government attribution."
        },
        {
          "claim": "ESET assesses with medium confidence that Operation RoundPress was conducted by Sednit.",
          "attributed_entity": "Sednit",
          "source": "eset-operation-roundpress-2025",
          "source_type": "vendor-research",
          "published_at": "2025-05-15T00:00:00.000Z",
          "confidence": "moderate",
          "status": "assessed",
          "notes": "The lower campaign-specific confidence is preserved despite broad high-confidence overlap between Sednit and APT28."
        }
      ],
      "targeting": {
        "regions": [
          "Europe",
          "North America",
          "Africa",
          "South America"
        ],
        "countries": [
          "Ukraine",
          "Poland",
          "Romania",
          "Slovakia",
          "Bulgaria",
          "Germany",
          "France",
          "United Kingdom",
          "United States"
        ],
        "sectors": [
          "Government",
          "Defence",
          "Military",
          "Diplomacy",
          "Logistics",
          "Transportation",
          "Maritime",
          "Air Traffic Management",
          "Information Technology",
          "Telecommunications",
          "Energy",
          "NGOs",
          "Research",
          "Education"
        ],
        "organisations": []
      },
      "campaigns": [
        "apt28-dns-hijacking",
        "operation-neusploit",
        "western-logistics-targeting",
        "operation-roundpress",
        "nearest-neighbor",
        "outlook-identity-collection",
        "promptsteal-ukraine",
        "cisco-router-reconnaissance"
      ],
      "malware": [
        "authentic-antics",
        "promptsteal",
        "gooseegg",
        "jaguar-tooth",
        "spypress",
        "headlace",
        "masepie",
        "minidoor",
        "pixynetloader"
      ],
      "tools": [
        "covenant-grunt"
      ],
      "techniques": [
        "password-spraying",
        "exploit-public-facing-application",
        "adversary-in-the-middle",
        "steal-application-access-token",
        "spearphishing-attachment",
        "spearphishing-link",
        "valid-accounts",
        "forced-authentication",
        "exploit-client-execution",
        "email-collection",
        "remote-email-collection",
        "com-hijacking",
        "scheduled-task",
        "powershell",
        "video-capture"
      ],
      "vulnerabilities": [
        {
          "cve": "CVE-2017-6742",
          "product": "Cisco IOS and IOS XE",
          "role": "Router initial access and Jaguar Tooth deployment",
          "campaign": "cisco-router-reconnaissance",
          "first_observed": "2021",
          "confidence": "high",
          "source": "ncsc-jaguar-tooth-2023",
          "notes": "Exploitation of the SNMP subsystem on unpatched Cisco devices."
        },
        {
          "cve": "CVE-2022-38028",
          "product": "Microsoft Windows Print Spooler",
          "role": "Post-compromise privilege escalation through GooseEgg",
          "campaign": "nearest-neighbor",
          "first_observed": "2019–2020",
          "confidence": "high",
          "source": "microsoft-gooseegg-2024",
          "notes": "Microsoft observed use since at least June 2020 and possibly April 2019."
        },
        {
          "cve": "CVE-2023-23397",
          "product": "Microsoft Outlook for Windows",
          "role": "Forced authentication and Net-NTLMv2 credential theft",
          "campaign": "western-logistics-targeting",
          "first_observed": "2022",
          "confidence": "high",
          "source": "microsoft-cve-2023-23397",
          "notes": "Exploitation can occur without the user opening the crafted message."
        },
        {
          "cve": "CVE-2023-38831",
          "product": "RARLAB WinRAR",
          "role": "Client-side initial access through crafted archives",
          "campaign": "western-logistics-targeting",
          "first_observed": "2023",
          "confidence": "high",
          "source": "cisa-aa25-141a",
          "notes": "Used in spearphishing against Ukrainian and logistics-related targets."
        },
        {
          "cve": "CVE-2023-43770",
          "product": "Roundcube Webmail",
          "role": "XSS execution inside the victim's webmail session",
          "campaign": "operation-roundpress",
          "first_observed": "2023",
          "confidence": "moderate",
          "source": "eset-operation-roundpress-2025",
          "notes": "Campaign attribution remains medium confidence."
        },
        {
          "cve": "CVE-2024-11182",
          "product": "MDaemon Webmail",
          "role": "Zero-day XSS delivery of SpyPress.MDAEMON",
          "campaign": "operation-roundpress",
          "first_observed": "2024",
          "confidence": "moderate",
          "source": "eset-operation-roundpress-2025",
          "notes": "ESET assessed the vulnerability was most likely discovered by Sednit."
        },
        {
          "cve": "CVE-2023-50224",
          "product": "TP-Link WR841N",
          "role": "Router credential disclosure followed by malicious DNS reconfiguration",
          "campaign": "apt28-dns-hijacking",
          "first_observed": "2024",
          "confidence": "high",
          "source": "ncsc-apt28-dns-2026",
          "notes": "NCSC states the actor likely used this vulnerability on the identified model."
        },
        {
          "cve": "CVE-2026-21509",
          "product": "Microsoft Office",
          "role": "Client-side exploitation and payload delivery",
          "campaign": "operation-neusploit",
          "first_observed": "2026-01",
          "confidence": "high",
          "source": "zscaler-operation-neusploit",
          "notes": "Active exploitation was observed three days after Microsoft's out-of-band update."
        },
        {
          "cve": "CVE-2026-21513",
          "product": "Microsoft MSHTML",
          "role": "Security-feature bypass associated with an in-the-wild exploit",
          "first_observed": "2026-01",
          "confidence": "moderate",
          "source": "akamai-cve-2026-21513",
          "notes": "Akamai linked the sample to APT28-associated infrastructure; APT Notes does not elevate that to direct government attribution."
        }
      ],
      "technique_evidence": [
        {
          "technique": "exploit-public-facing-application",
          "campaign": "apt28-dns-hijacking",
          "first_observed": "2024",
          "last_observed": "2026",
          "confidence": "high",
          "sources": [
            "ncsc-apt28-dns-2026"
          ],
          "notes": "Exploitation of internet-facing routers to create operational infrastructure."
        },
        {
          "technique": "adversary-in-the-middle",
          "campaign": "apt28-dns-hijacking",
          "first_observed": "2024",
          "last_observed": "2026",
          "confidence": "high",
          "sources": [
            "ncsc-apt28-dns-2026",
            "microsoft-soho-dns-2026"
          ],
          "notes": "Selective DNS resolution enabled interception of passwords and OAuth tokens."
        },
        {
          "technique": "spearphishing-attachment",
          "campaign": "operation-neusploit",
          "first_observed": "2026-01",
          "last_observed": "2026-02",
          "confidence": "high",
          "sources": [
            "zscaler-operation-neusploit"
          ],
          "notes": "Weaponised RTF documents exploited CVE-2026-21509."
        },
        {
          "technique": "remote-email-collection",
          "campaign": "western-logistics-targeting",
          "first_observed": "2022",
          "last_observed": "2025",
          "confidence": "high",
          "sources": [
            "cisa-aa25-141a"
          ],
          "notes": "EWS and IMAP supported periodic, long-term collection."
        },
        {
          "technique": "steal-application-access-token",
          "campaign": "outlook-identity-collection",
          "first_observed": "2023",
          "last_observed": "2025",
          "confidence": "high",
          "sources": [
            "ncsc-authentic-antics-2025"
          ],
          "notes": "AUTHENTIC ANTICS intercepted OAuth authorization flows from within Outlook."
        },
        {
          "technique": "video-capture",
          "campaign": "western-logistics-targeting",
          "first_observed": "2022",
          "last_observed": "2025",
          "confidence": "high",
          "sources": [
            "cisa-aa25-141a"
          ],
          "notes": "RTSP-accessible cameras were targeted around logistics and military locations."
        }
      ],
      "operational_timeline": [
        {
          "date": "2004–2007",
          "title": "Long-running strategic espionage activity emerges",
          "summary": "Public tracking places activity associated with APT28 in operation since at least 2004, with early vendor visibility focused on government, military and security intelligence.",
          "confidence": "high",
          "sources": [
            "mitre-g0007"
          ]
        },
        {
          "date": "2014–2018",
          "title": "Remote and close-access operations become public",
          "summary": "Legal cases documented operations against anti-doping, sporting and chemical-analysis organisations, including on-site wireless access attempts.",
          "confidence": "high",
          "sources": [
            "doj-gru-indictment-2018"
          ]
        },
        {
          "date": "2021–2023",
          "title": "Network devices become operational infrastructure",
          "summary": "APT28 exploited Cisco routers, deployed Jaguar Tooth and later repurposed criminally compromised EdgeRouters to conceal credential operations.",
          "confidence": "high",
          "sources": [
            "ncsc-jaguar-tooth-2023",
            "doj-soho-botnet-2024"
          ]
        },
        {
          "date": "2022–2025",
          "title": "Ukraine-support logistics and physical movement collection",
          "summary": "Unit 26165 targeted logistics, transport and technology relationships while also probing cameras near border, rail and military locations.",
          "confidence": "high",
          "sources": [
            "cisa-aa25-141a"
          ]
        },
        {
          "date": "2023–2025",
          "title": "Webmail, Outlook and cloud identity collection",
          "summary": "Public reporting documented RoundPress, CVE-2023-23397 exploitation and AUTHENTIC ANTICS credential and OAuth-token theft.",
          "confidence": "high",
          "sources": [
            "eset-operation-roundpress-2025",
            "microsoft-cve-2023-23397",
            "ncsc-authentic-antics-2025"
          ]
        },
        {
          "date": "2025",
          "title": "LLM-assisted malware enters live operations",
          "summary": "PROMPTSTEAL queried an external language model for discovery and collection commands during activity against Ukraine.",
          "confidence": "high",
          "sources": [
            "gtig-promptsteal-2025"
          ]
        },
        {
          "date": "2026",
          "title": "Rapid Office exploitation and selective payload delivery",
          "summary": "Operation Neusploit used CVE-2026-21509, regional geofencing and multiple payload chains against Central and Eastern European targets.",
          "confidence": "high",
          "sources": [
            "zscaler-operation-neusploit"
          ]
        },
        {
          "date": "2024–2026",
          "title": "Router compromise enables DNS and authentication interception",
          "summary": "Compromised SOHO devices redirected selected authentication traffic through malicious DNS and adversary-in-the-middle infrastructure.",
          "confidence": "high",
          "sources": [
            "ncsc-apt28-dns-2026",
            "microsoft-soho-dns-2026",
            "doj-operation-masquerade-2026"
          ]
        }
      ],
      "external_identifiers": {
        "mitre_attack": "G0007",
        "other": [
          "GRU Unit 26165"
        ]
      },
      "related_research": [],
      "sources": [
        "ncsc-apt28-dns-2026",
        "microsoft-soho-dns-2026",
        "doj-operation-masquerade-2026",
        "zscaler-operation-neusploit",
        "akamai-cve-2026-21513",
        "gtig-promptsteal-2025",
        "ncsc-authentic-antics-2025",
        "eset-operation-roundpress-2025",
        "cisa-aa25-141a",
        "volexity-nearest-neighbor-2024",
        "microsoft-gooseegg-2024",
        "microsoft-cve-2023-23397",
        "doj-soho-botnet-2024",
        "mandiant-apt44-correction-2024",
        "ncsc-jaguar-tooth-2023",
        "doj-gru-indictment-2018",
        "mitre-g0007"
      ],
      "updates": [
        "apt28-profile-created",
        "apt28-major-review-2026"
      ],
      "featured": true,
      "url": "https://apt.hecavex.com/actors/apt28/",
      "json_url": "https://apt.hecavex.com/api/actors/apt28.json"
    },
    {
      "id": "apt44",
      "name": "APT44",
      "slug": "apt44",
      "summary": "A Russian military intelligence intrusion set associated with GRU Unit 74455 and a full-spectrum mission spanning strategic access, espionage, destructive attacks, operational-technology disruption and influence activity.",
      "draft": false,
      "actor_types": [
        "state-sponsored"
      ],
      "status": "active",
      "suspected_origins": [
        "Russia"
      ],
      "motivations": [
        "espionage",
        "disruption",
        "destruction",
        "influence",
        "credential-access",
        "data-theft"
      ],
      "active_since": "2009",
      "last_observed": "2026",
      "confidence": "high",
      "last_reviewed": "2026-08-09T00:00:00.000Z",
      "authors": [
        "deividas-lis"
      ],
      "mission": "Obtain and preserve access, collect intelligence, disrupt or destroy selected systems and amplify operational effects in support of Russian military and state objectives.",
      "current_assessment": "APT44 remains an active full-spectrum threat. Current public reporting shows two complementary priorities: scalable access to internet-facing infrastructure that can be retained for strategic use, and intelligence collection from defence-related systems, battlefield platforms and private messaging data. Its history means retained access must be evaluated for both espionage and destructive follow-on risk.",
      "aliases": [
        {
          "name": "Sandworm Team",
          "source": "Government and industry reporting",
          "relationship": "common-alias",
          "confidence": "high",
          "scope": "Broad public designation for activity associated with GRU Unit 74455.",
          "first_seen": "2014 public naming",
          "last_seen": "2026",
          "notes": "The name predates Mandiant's APT44 designation and remains widely used."
        },
        {
          "name": "Seashell Blizzard",
          "source": "Microsoft",
          "relationship": "vendor-tracking-cluster",
          "confidence": "high",
          "scope": "Microsoft cluster overlapping APT44 and Unit 74455 activity.",
          "first_seen": "2023 naming",
          "last_seen": "2025",
          "notes": "Previously tracked by Microsoft as IRIDIUM."
        },
        {
          "name": "FROZENBARENTS",
          "source": "Google Threat Intelligence Group",
          "relationship": "vendor-tracking-cluster",
          "confidence": "high",
          "scope": "Google tracking designation used for activity now included in APT44.",
          "first_seen": "historical",
          "last_seen": "2026",
          "notes": "Vendor boundaries may be narrower than the complete analytic record."
        },
        {
          "name": "IRIDIUM",
          "source": "Microsoft",
          "relationship": "historical-designation",
          "confidence": "high",
          "scope": "Former Microsoft designation replaced by Seashell Blizzard.",
          "first_seen": "historical",
          "last_seen": "2023",
          "notes": "Retained for searching historical Microsoft reporting."
        },
        {
          "name": "Voodoo Bear",
          "source": "Government and industry reporting",
          "relationship": "common-alias",
          "confidence": "high",
          "scope": "Public alias associated with Unit 74455 operations.",
          "first_seen": "historical",
          "last_seen": "2022",
          "notes": "Used in joint government reporting on Cyclops Blink."
        },
        {
          "name": "TeleBots",
          "source": "ESET and industry reporting",
          "relationship": "vendor-tracking-cluster",
          "confidence": "high",
          "scope": "Historical cluster associated with disruptive activity and related tooling.",
          "first_seen": "historical",
          "last_seen": "2024",
          "notes": "Some reporting uses the name for a subset of the broader activity."
        },
        {
          "name": "BlackEnergy Group",
          "source": "Industry reporting",
          "relationship": "historical-designation",
          "confidence": "high",
          "scope": "Historical activity cluster connected to Ukrainian power-sector intrusions.",
          "first_seen": "historical",
          "last_seen": "2016",
          "notes": "The BlackEnergy malware family and actor label should not be treated as interchangeable in every source."
        },
        {
          "name": "ELECTRUM",
          "source": "Dragos",
          "relationship": "research-cluster",
          "confidence": "high",
          "scope": "Research designation associated with Sandworm's electric-power operations.",
          "first_seen": "historical",
          "last_seen": "2024",
          "notes": "Primarily useful in OT-focused reporting."
        }
      ],
      "parent_entities": [
        {
          "name": "GRU Main Centre for Special Technologies, Military Unit 74455",
          "entity_type": "Russian military intelligence unit",
          "relationship": "attributed operator",
          "confidence": "high",
          "source": "doj-sandworm-indictment-2020",
          "notes": "The United States charged Unit 74455 officers in connection with destructive and disruptive operations publicly tracked as Sandworm activity."
        }
      ],
      "subclusters": [
        {
          "name": "BadPilot initial-access subgroup",
          "source": "Microsoft Threat Intelligence",
          "relationship": "subgroup",
          "confidence": "high",
          "notes": "Microsoft distinguishes this horizontally scalable access operation from the entirety of Seashell Blizzard activity."
        }
      ],
      "attribution": [
        {
          "claim": "The United States charged six GRU Unit 74455 officers with destructive and disruptive operations publicly tracked as Sandworm Team, TeleBots, Voodoo Bear and Iron Viking.",
          "attributed_entity": "GRU Military Unit 74455",
          "source": "doj-sandworm-indictment-2020",
          "source_type": "legal",
          "published_at": "2020-10-19T00:00:00.000Z",
          "confidence": "high",
          "status": "reported",
          "notes": "The source is a charging announcement. The allegations are not recorded as judicial findings."
        },
        {
          "claim": "The NCSC, CISA, FBI and NSA attribute Sandworm to the Russian GRU Main Centre for Special Technologies.",
          "attributed_entity": "GRU Main Centre for Special Technologies, Military Unit 74455",
          "source": "ncsc-cyclops-blink-2022",
          "source_type": "government",
          "published_at": "2022-02-23T00:00:00.000Z",
          "confidence": "high",
          "status": "assessed",
          "notes": "Joint government attribution associated with the Cyclops Blink advisory."
        },
        {
          "claim": "Mandiant assesses that APT44 is sponsored by Russian military intelligence and combines espionage, attack and influence operations.",
          "attributed_entity": "Russian military intelligence",
          "source": "gtig-apt44-2024",
          "source_type": "vendor-research",
          "published_at": "2024-04-17T00:00:00.000Z",
          "confidence": "high",
          "status": "assessed",
          "notes": "This assessment defines the APT44 analytic umbrella used by this profile."
        },
        {
          "claim": "Microsoft links Seashell Blizzard and its BadPilot initial-access subgroup to operations conducted on behalf of GRU Unit 74455.",
          "attributed_entity": "GRU Military Unit 74455",
          "source": "microsoft-badpilot-2025",
          "source_type": "vendor-research",
          "published_at": "2025-02-12T00:00:00.000Z",
          "confidence": "high",
          "status": "assessed",
          "notes": "The subgroup relationship should not be expanded to every opportunistic compromise without supporting evidence."
        }
      ],
      "targeting": {
        "regions": [
          "Ukraine",
          "Europe",
          "North America",
          "Central Asia",
          "South Asia",
          "Middle East",
          "Australia",
          "Global"
        ],
        "countries": [
          "Ukraine",
          "Poland",
          "Georgia",
          "France",
          "United Kingdom",
          "United States",
          "Canada",
          "Australia",
          "South Korea"
        ],
        "sectors": [
          "Government",
          "Military",
          "Defence",
          "Energy",
          "Electric Power",
          "Oil and Gas",
          "Water",
          "Telecommunications",
          "Transportation",
          "Logistics",
          "Shipping",
          "Manufacturing",
          "Information Technology",
          "Media",
          "Civil Society",
          "Critical Infrastructure"
        ],
        "organisations": []
      },
      "campaigns": [
        "badpilot",
        "ukraine-electric-power-2022",
        "prestige-ransomware",
        "notpetya-operation"
      ],
      "malware": [
        "localolive",
        "cyclops-blink",
        "caddywiper",
        "prestige",
        "notpetya",
        "wavesign"
      ],
      "tools": [
        "shadowlink",
        "rclone"
      ],
      "techniques": [
        "exploit-public-facing-application",
        "server-software-component-web-shell",
        "external-remote-services",
        "remote-access-software",
        "os-credential-dumping-lsass",
        "valid-accounts",
        "data-from-local-system",
        "powershell",
        "scheduled-task",
        "data-destruction",
        "lateral-tool-transfer",
        "systemd-service",
        "supply-chain-compromise"
      ],
      "vulnerabilities": [
        {
          "cve": "CVE-2021-34473",
          "product": "Microsoft Exchange Server",
          "role": "Initial access followed by web-shell deployment",
          "campaign": "badpilot",
          "first_observed": "2021",
          "confidence": "high",
          "source": "microsoft-badpilot-2025",
          "notes": "Microsoft observed web-shell retrieval and deployment after exploitation."
        },
        {
          "cve": "CVE-2022-41352",
          "product": "Zimbra Collaboration",
          "role": "Arbitrary file write used to place a web shell",
          "campaign": "badpilot",
          "first_observed": "2022-10-24",
          "confidence": "high",
          "source": "microsoft-badpilot-2025",
          "notes": "Exploitation used crafted email attachments to write files to the server."
        },
        {
          "cve": "CVE-2023-32315",
          "product": "Openfire",
          "role": "Perimeter-service exploitation for initial access",
          "campaign": "badpilot",
          "first_observed": "2023",
          "confidence": "high",
          "source": "microsoft-badpilot-2025",
          "notes": "Included in Microsoft's observed vulnerability set for the subgroup."
        },
        {
          "cve": "CVE-2023-42793",
          "product": "JetBrains TeamCity",
          "role": "Perimeter-service exploitation for initial access",
          "campaign": "badpilot",
          "first_observed": "2023",
          "confidence": "high",
          "source": "microsoft-badpilot-2025",
          "notes": "Included in Microsoft's observed vulnerability set for the subgroup."
        },
        {
          "cve": "CVE-2023-23397",
          "product": "Microsoft Outlook for Windows",
          "role": "Credential access supporting follow-on compromise",
          "campaign": "badpilot",
          "first_observed": "2023",
          "confidence": "high",
          "source": "microsoft-badpilot-2025",
          "notes": "Recorded specifically within Microsoft's subgroup reporting; the vulnerability has also been used by other actors."
        },
        {
          "cve": "CVE-2024-1709",
          "product": "ConnectWise ScreenConnect",
          "role": "Remote command execution followed by RMM deployment",
          "campaign": "badpilot",
          "first_observed": "2024-02-24",
          "confidence": "high",
          "source": "microsoft-badpilot-2025",
          "notes": "Follow-on activity included Atera Agent, credential access and additional persistence."
        },
        {
          "cve": "CVE-2023-48788",
          "product": "Fortinet FortiClient EMS",
          "role": "Remote command execution followed by RMM deployment",
          "campaign": "badpilot",
          "first_observed": "2024-04",
          "confidence": "high",
          "source": "microsoft-badpilot-2025",
          "notes": "Microsoft observed Atera retrieval from actor-controlled infrastructure during April 2024 exploitation."
        }
      ],
      "technique_evidence": [
        {
          "technique": "exploit-public-facing-application",
          "campaign": "badpilot",
          "first_observed": "2021",
          "last_observed": "2025 reporting",
          "confidence": "high",
          "sources": [
            "microsoft-badpilot-2025"
          ],
          "notes": "Seven named CVEs and one JBoss exploitation pattern are recorded in the public report."
        },
        {
          "technique": "server-software-component-web-shell",
          "campaign": "badpilot",
          "first_observed": "2021",
          "last_observed": "2025 reporting",
          "confidence": "high",
          "sources": [
            "microsoft-badpilot-2025"
          ],
          "notes": "Web shells remained the subgroup's predominant persistence method when reported."
        },
        {
          "technique": "external-remote-services",
          "campaign": "badpilot",
          "first_observed": "2021",
          "last_observed": "2025 reporting",
          "confidence": "high",
          "sources": [
            "microsoft-badpilot-2025",
            "ncsc-cyclops-blink-2022"
          ],
          "notes": "Evidence includes OpenSSH, Tor-based access and network-device infrastructure."
        },
        {
          "technique": "remote-access-software",
          "campaign": "badpilot",
          "first_observed": "2024",
          "last_observed": "2025 reporting",
          "confidence": "high",
          "sources": [
            "microsoft-badpilot-2025"
          ],
          "notes": "Atera Agent and Splashtop were used as legitimate-looking persistence and command channels."
        },
        {
          "technique": "os-credential-dumping-lsass",
          "campaign": "badpilot",
          "first_observed": "2024",
          "last_observed": "2025 reporting",
          "confidence": "high",
          "sources": [
            "microsoft-badpilot-2025"
          ],
          "notes": "Evidence includes renamed ProcDump and interactive access compatible with Task Manager dumping."
        },
        {
          "technique": "valid-accounts",
          "campaign": "prestige-ransomware",
          "first_observed": "2022",
          "last_observed": "2025 reporting",
          "confidence": "high",
          "sources": [
            "microsoft-prestige-2022",
            "microsoft-badpilot-2025"
          ],
          "notes": "Credential access and retained identities support durable follow-on operations."
        },
        {
          "technique": "data-from-local-system",
          "first_observed": "2023",
          "last_observed": "2026 reporting",
          "confidence": "high",
          "sources": [
            "gtig-defense-industrial-base-2026"
          ],
          "notes": "WAVESIGN collected Signal Desktop data; the public report also describes attempts to obtain Telegram and Signal information from devices."
        },
        {
          "technique": "powershell",
          "campaign": "ukraine-electric-power-2022",
          "first_observed": "2022",
          "last_observed": "2022",
          "confidence": "high",
          "sources": [
            "mandiant-ukraine-power-2023",
            "mitre-g0034"
          ],
          "notes": "TANKTRAP used PowerShell and Group Policy to distribute a wiper."
        },
        {
          "technique": "scheduled-task",
          "campaign": "ukraine-electric-power-2022",
          "first_observed": "2022",
          "last_observed": "2022",
          "confidence": "high",
          "sources": [
            "mandiant-ukraine-power-2023",
            "microsoft-prestige-2022"
          ],
          "notes": "Scheduled execution appears in separate destructive deployment chains."
        },
        {
          "technique": "data-destruction",
          "campaign": "ukraine-electric-power-2022",
          "first_observed": "2015",
          "last_observed": "2022",
          "confidence": "high",
          "sources": [
            "doj-sandworm-indictment-2020",
            "mandiant-ukraine-power-2023",
            "microsoft-prestige-2022"
          ],
          "notes": "The profile separates destructive payload deployment from the mechanism that caused each operational outage."
        },
        {
          "technique": "lateral-tool-transfer",
          "campaign": "prestige-ransomware",
          "first_observed": "2015",
          "last_observed": "2022",
          "confidence": "high",
          "sources": [
            "microsoft-prestige-2022",
            "mandiant-ukraine-power-2023",
            "mitre-g0034"
          ],
          "notes": "Includes Group Policy, network shares and transfer between IT and OT systems."
        },
        {
          "technique": "systemd-service",
          "campaign": "ukraine-electric-power-2022",
          "first_observed": "2022",
          "last_observed": "2022",
          "confidence": "high",
          "sources": [
            "mandiant-ukraine-power-2023",
            "mitre-g0034"
          ],
          "notes": "GOGETTER used service units that masqueraded as legitimate Linux services."
        },
        {
          "technique": "supply-chain-compromise",
          "campaign": "notpetya-operation",
          "first_observed": "2017",
          "last_observed": "2017",
          "confidence": "high",
          "sources": [
            "doj-sandworm-indictment-2020",
            "gtig-apt44-2024",
            "mitre-g0034"
          ],
          "notes": "The trusted update mechanism enabled initial distribution before broader propagation."
        }
      ],
      "operational_timeline": [
        {
          "date": "2009-2014",
          "title": "Early activity and public Sandworm naming",
          "summary": "Public tracking places the cluster in operation since at least 2009; the Sandworm name entered industry reporting before later government attribution.",
          "confidence": "high",
          "sources": [
            "gtig-apt44-2024",
            "mitre-g0034"
          ]
        },
        {
          "date": "2015-2016",
          "title": "Ukrainian electric-power disruptions",
          "summary": "Operations associated with the group disrupted Ukrainian power distribution and demonstrated purpose-built capability against operational technology.",
          "confidence": "high",
          "sources": [
            "doj-sandworm-indictment-2020",
            "gtig-apt44-2024",
            "mitre-g0034"
          ]
        },
        {
          "date": "2017",
          "title": "NotPetya escapes its initial Ukrainian distribution context",
          "summary": "A compromised software-update mechanism delivered a destructive payload that spread internationally and caused extensive collateral damage.",
          "confidence": "high",
          "sources": [
            "doj-sandworm-indictment-2020",
            "gtig-apt44-2024"
          ]
        },
        {
          "date": "2018",
          "title": "Olympic Destroyer and retaliation beyond Ukraine",
          "summary": "The United States charged Unit 74455 officers in connection with destructive activity against the PyeongChang Winter Olympics and related spearphishing.",
          "confidence": "high",
          "sources": [
            "doj-sandworm-indictment-2020"
          ]
        },
        {
          "date": "2019-2022",
          "title": "Network-device persistence and wartime destructive operations",
          "summary": "Cyclops Blink provided modular firmware persistence while operations in Ukraine included electric-power disruption, wipers and the Prestige attacks affecting Ukraine and Poland.",
          "confidence": "high",
          "sources": [
            "ncsc-cyclops-blink-2022",
            "mandiant-ukraine-power-2023",
            "microsoft-prestige-2022"
          ]
        },
        {
          "date": "2024",
          "title": "APT44 analytic consolidation",
          "summary": "Mandiant introduced APT44 as the umbrella for a full-spectrum actor and corrected previously conflated APT28 activity after reanalysis of shared victim access.",
          "confidence": "high",
          "sources": [
            "gtig-apt44-2024",
            "mandiant-apt44-correction-2024"
          ]
        },
        {
          "date": "2025",
          "title": "BadPilot exposes a scalable access layer",
          "summary": "Microsoft documented a subgroup exploiting perimeter applications, deploying web shells and legitimate remote-management tools, and preserving access for selected strategic operations.",
          "confidence": "high",
          "sources": [
            "microsoft-badpilot-2025"
          ]
        },
        {
          "date": "2026",
          "title": "Defence and battlefield intelligence collection remains visible",
          "summary": "GTIG reported continued attempts to collect Signal and Telegram data and target battlefield-management and defence-related technology.",
          "confidence": "high",
          "sources": [
            "gtig-defense-industrial-base-2026"
          ]
        }
      ],
      "external_identifiers": {
        "mitre_attack": "G0034",
        "other": [
          "GRU Unit 74455",
          "GTsST"
        ]
      },
      "related_research": [],
      "sources": [
        "gtig-defense-industrial-base-2026",
        "microsoft-badpilot-2025",
        "gtig-apt44-2024",
        "mitre-g0034",
        "doj-sandworm-indictment-2020",
        "ncsc-cyclops-blink-2022",
        "mandiant-ukraine-power-2023",
        "microsoft-prestige-2022",
        "mandiant-apt44-correction-2024"
      ],
      "updates": [
        "apt44-profile-created"
      ],
      "featured": true,
      "url": "https://apt.hecavex.com/actors/apt44/",
      "json_url": "https://apt.hecavex.com/api/actors/apt44.json"
    },
    {
      "id": "unit-29155",
      "name": "GRU Unit 29155",
      "slug": "unit-29155",
      "summary": "A Russian military intelligence unit associated with espionage, sabotage, reputational harm and the destructive WhisperGate operation against Ukraine.",
      "draft": false,
      "actor_types": [
        "state-sponsored"
      ],
      "status": "active",
      "suspected_origins": [
        "Russia"
      ],
      "motivations": [
        "espionage",
        "disruption",
        "destruction",
        "data-theft",
        "credential-access"
      ],
      "active_since": "2020",
      "last_observed": "2024 public reporting",
      "confidence": "high",
      "last_reviewed": "2026-08-14T00:00:00.000Z",
      "authors": [
        "deividas-lis"
      ],
      "mission": "Conduct computer-network operations supporting Russian military intelligence objectives through reconnaissance, access, collection, sabotage and reputational effects against Ukraine, NATO members and global critical infrastructure.",
      "current_assessment": "Public government and legal reporting establishes Unit 29155 as a distinct GRU cyber actor whose activity spans destructive effects and conventional intrusion tradecraft. Its broad scanning and exploitation create opportunities, while target selection and follow-on actions determine whether an intrusion becomes espionage, theft, disruption or destruction.",
      "aliases": [
        {
          "name": "Ember Bear",
          "source": "MITRE ATT&CK",
          "relationship": "research-cluster",
          "confidence": "high",
          "scope": "ATT&CK group mapped to Unit 29155-linked activity since at least 2020.",
          "first_seen": "2020",
          "last_seen": "2025 ATT&CK review",
          "notes": "MITRE explicitly distinguishes Ember Bear from Saint Bear despite historical confusion."
        },
        {
          "name": "Cadet Blizzard",
          "source": "Microsoft",
          "relationship": "vendor-tracking-cluster",
          "confidence": "high",
          "scope": "Microsoft cluster associated in the joint government advisory with Unit 29155 activity.",
          "first_seen": "2022 naming",
          "last_seen": "2024 reporting",
          "notes": "Formerly tracked as DEV-0586."
        },
        {
          "name": "UNC2589",
          "source": "Mandiant",
          "relationship": "vendor-tracking-cluster",
          "confidence": "high",
          "scope": "Research cluster associated with overlapping Ukraine-focused espionage and disruptive activity.",
          "first_seen": "2021",
          "last_seen": "2024 government reporting",
          "notes": "Preserve source context because historical reporting did not always make the same attribution claim."
        },
        {
          "name": "Bleeding Bear",
          "source": "CrowdStrike",
          "relationship": "vendor-tracking-cluster",
          "confidence": "moderate",
          "scope": "Industry cluster included as overlapping reporting in the joint advisory.",
          "first_seen": "historical",
          "last_seen": "2024 reporting",
          "notes": "Cluster boundaries may differ from the government activity grouping."
        },
        {
          "name": "UAC-0056",
          "source": "CERT-UA and industry reporting",
          "relationship": "vendor-tracking-cluster",
          "confidence": "moderate",
          "scope": "Ukraine-focused activity mapped by public reporting to the broader Unit 29155 cluster.",
          "first_seen": "2021",
          "last_seen": "2024 reporting",
          "notes": "This identifier has also been used in reporting that requires care around Saint Bear versus Ember Bear distinctions."
        }
      ],
      "parent_entities": [
        {
          "name": "GRU 161st Specialist Training Center, Military Unit 29155",
          "entity_type": "Russian military intelligence unit",
          "relationship": "attributed operator",
          "confidence": "high",
          "source": "cisa-aa24-249a",
          "notes": "The joint advisory attributes the reported activity to the GRU 161st Specialist Training Center, Unit 29155."
        }
      ],
      "subclusters": [],
      "attribution": [
        {
          "claim": "A multinational advisory attributes the described global cyber activity to the GRU 161st Specialist Training Center, Unit 29155.",
          "attributed_entity": "GRU Unit 29155",
          "source": "cisa-aa24-249a",
          "source_type": "government",
          "published_at": "2024-09-05T00:00:00.000Z",
          "confidence": "high",
          "status": "assessed",
          "notes": "The advisory combines government holdings and overlapping industry reporting and warns that tracking names may not map one-to-one."
        },
        {
          "claim": "The United States charged five Unit 29155 officers and a civilian for alleged intrusions connected to WhisperGate and related activity.",
          "attributed_entity": "GRU Unit 29155 personnel",
          "source": "doj-unit-29155-2024",
          "source_type": "legal",
          "published_at": "2024-09-05T00:00:00.000Z",
          "confidence": "high",
          "status": "reported",
          "notes": "These are allegations in charging documents, not findings of guilt."
        }
      ],
      "targeting": {
        "regions": [
          "Eastern Europe",
          "Europe",
          "North America",
          "Latin America",
          "Central Asia"
        ],
        "countries": [
          "Ukraine",
          "United States",
          "Albania",
          "Czech Republic",
          "Germany",
          "Estonia",
          "Latvia",
          "Lithuania",
          "Poland",
          "Slovakia"
        ],
        "sectors": [
          "Government",
          "Critical Infrastructure",
          "Financial Services",
          "Transportation",
          "Energy",
          "Healthcare",
          "Telecommunications"
        ],
        "organisations": []
      },
      "campaigns": [
        "whispergate-operation"
      ],
      "malware": [
        "whispergate"
      ],
      "tools": [
        "rclone"
      ],
      "techniques": [
        "password-spraying",
        "exploit-public-facing-application",
        "external-remote-services",
        "valid-accounts",
        "powershell",
        "data-from-local-system",
        "scheduled-task",
        "external-defacement",
        "disk-structure-wipe",
        "exfiltration-cloud-storage"
      ],
      "vulnerabilities": [
        {
          "cve": "CVE-2021-33044",
          "product": "Dahua IP cameras",
          "role": "Initial access to internet-facing devices",
          "first_observed": "2022 or earlier reporting window",
          "confidence": "high",
          "source": "cisa-aa24-249a",
          "notes": "The joint advisory lists this vulnerability as exploited. It separately lists several exploit scripts obtained but not confirmed exploited."
        },
        {
          "cve": "CVE-2021-33045",
          "product": "Dahua IP cameras",
          "role": "Initial access to internet-facing devices",
          "first_observed": "2022 or earlier reporting window",
          "confidence": "high",
          "source": "cisa-aa24-249a",
          "notes": "The advisory's observed-exploitation wording is preserved."
        }
      ],
      "technique_evidence": [
        {
          "technique": "exploit-public-facing-application",
          "first_observed": "2020",
          "last_observed": "2024 reporting",
          "confidence": "high",
          "sources": [
            "cisa-aa24-249a"
          ],
          "notes": "Public reporting describes broad reconnaissance followed by exploitation of exposed services and devices."
        },
        {
          "technique": "password-spraying",
          "first_observed": "2020",
          "last_observed": "2024 reporting",
          "confidence": "high",
          "sources": [
            "cisa-aa24-249a",
            "mitre-g1003"
          ],
          "notes": "Password spraying against webmail and other externally accessible identity surfaces supported account access."
        },
        {
          "technique": "exfiltration-cloud-storage",
          "first_observed": "2020",
          "last_observed": "2024 reporting",
          "confidence": "high",
          "sources": [
            "cisa-aa24-249a",
            "mitre-g1003"
          ],
          "notes": "Rclone and cloud storage appear in public descriptions of data transfer."
        },
        {
          "technique": "disk-structure-wipe",
          "campaign": "whispergate-operation",
          "first_observed": "2022-01",
          "last_observed": "2022",
          "confidence": "high",
          "sources": [
            "cisa-aa24-249a",
            "doj-unit-29155-2024",
            "mitre-g1003"
          ],
          "notes": "WhisperGate masqueraded as ransomware while destroying disk structures and data."
        }
      ],
      "operational_timeline": [
        {
          "date": "2020-2021",
          "title": "Reconnaissance and intrusion activity becomes visible",
          "summary": "Joint reporting places the unit's cyber operations against global targets from at least 2020, using scanning, vulnerability research, password attacks and legitimate administration tools.",
          "confidence": "high",
          "sources": [
            "cisa-aa24-249a",
            "mitre-g1003"
          ]
        },
        {
          "date": "2022-01",
          "title": "WhisperGate and website defacement precede the invasion",
          "summary": "Ukrainian government systems were defaced, data was taken and destructive malware was deployed under a false ransomware narrative.",
          "confidence": "high",
          "sources": [
            "cisa-aa24-249a",
            "doj-unit-29155-2024",
            "mitre-g1003"
          ]
        },
        {
          "date": "2022-2024",
          "title": "Activity expands across NATO and critical infrastructure targets",
          "summary": "The multinational advisory describes post-WhisperGate reconnaissance and intrusions affecting transportation, energy, government, financial and healthcare targets beyond Ukraine.",
          "confidence": "high",
          "sources": [
            "cisa-aa24-249a"
          ]
        },
        {
          "date": "2024-09",
          "title": "Multinational attribution and criminal charges become public",
          "summary": "Governments published the technical advisory while the United States unsealed charges naming Unit 29155 personnel and a civilian collaborator.",
          "confidence": "high",
          "sources": [
            "cisa-aa24-249a",
            "doj-unit-29155-2024"
          ]
        }
      ],
      "external_identifiers": {
        "mitre_attack": "G1003",
        "other": [
          "GRU Unit 29155",
          "161st Specialist Training Center"
        ]
      },
      "related_research": [],
      "sources": [
        "cisa-aa24-249a",
        "doj-unit-29155-2024",
        "mitre-g1003"
      ],
      "updates": [
        "unit-29155-profile-created"
      ],
      "featured": true,
      "url": "https://apt.hecavex.com/actors/unit-29155/",
      "json_url": "https://apt.hecavex.com/api/actors/unit-29155.json"
    },
    {
      "id": "void-blizzard",
      "name": "Void Blizzard",
      "slug": "void-blizzard",
      "summary": "A Russia-affiliated espionage cluster using commodity credentials, stolen session cookies and cloud-native collection against NATO, EU and Ukraine-related targets.",
      "draft": false,
      "actor_types": [
        "state-sponsored"
      ],
      "status": "active",
      "suspected_origins": [
        "Russia"
      ],
      "motivations": [
        "espionage",
        "credential-access",
        "data-theft"
      ],
      "active_since": "2024-04",
      "last_observed": "2026-07",
      "confidence": "high",
      "last_reviewed": "2026-08-14T00:00:00.000Z",
      "authors": [
        "deividas-lis"
      ],
      "mission": "Collect government, defence, logistics, technology, policy and Ukraine-support information from Western organisations through scalable identity compromise and cloud data access.",
      "current_assessment": "Void Blizzard combines scalable identity abuse with a growing technical collection capability. Purchased credentials, stolen cookies, password spraying and legitimate cloud APIs remain central, while the 2025–2026 Zimbra campaign demonstrates access to a novel exploit and custom collection infrastructure.",
      "aliases": [
        {
          "name": "Laundry Bear",
          "source": "AIVD and MIVD",
          "relationship": "government-designation",
          "confidence": "high",
          "scope": "Dutch intelligence-service name for the actor Microsoft tracks as Void Blizzard.",
          "first_seen": "2024",
          "last_seen": "2026",
          "notes": "The two investigations were conducted in collaboration and explicitly cross-reference the names."
        },
        {
          "name": "CL-STA-1114",
          "source": "Palo Alto Networks Unit 42, as cited in the 2026 joint advisory",
          "relationship": "vendor-tracking-cluster",
          "confidence": "moderate",
          "scope": "Industry activity cluster listed as overlapping with the government understanding of Laundry Bear.",
          "first_seen": "public reporting",
          "last_seen": "2026 advisory",
          "notes": "The joint advisory explicitly cautions that industry names may not correlate one-to-one."
        },
        {
          "name": "TA488",
          "source": "Proofpoint, as cited in the 2026 joint advisory",
          "relationship": "vendor-tracking-cluster",
          "confidence": "moderate",
          "scope": "Industry cluster formerly named UNK_PitStop and listed as overlapping Laundry Bear activity.",
          "first_seen": "public reporting",
          "last_seen": "2026 advisory",
          "notes": "Retained as a search pivot, not asserted as exact equivalence across every historical operation."
        }
      ],
      "parent_entities": [],
      "subclusters": [],
      "attribution": [
        {
          "claim": "Microsoft assesses with high confidence that Void Blizzard is Russia-affiliated and disproportionately targets NATO members and Ukraine.",
          "attributed_entity": "Russia-affiliated threat actor",
          "source": "microsoft-void-blizzard-2025",
          "source_type": "vendor-research",
          "published_at": "2025-05-27T00:00:00.000Z",
          "confidence": "high",
          "status": "assessed",
          "notes": "Microsoft does not publicly assign the cluster to a named Russian intelligence service or unit."
        },
        {
          "claim": "The Dutch services assess Laundry Bear is highly probably a Russian state-supported actor conducting espionage against Western organisations.",
          "attributed_entity": "Russian state-supported threat actor",
          "source": "aivd-mivd-laundry-bear-2025",
          "source_type": "government",
          "published_at": "2025-05-27T00:00:00.000Z",
          "confidence": "high",
          "status": "assessed",
          "notes": "The actor's precise organisational sponsor remains undisclosed in the public report."
        },
        {
          "claim": "A multinational joint advisory attributes the Zimbra campaign exploiting CVE-2025-66376 to Russian state-supported actors primarily tracked as Laundry Bear.",
          "attributed_entity": "Laundry Bear",
          "source": "joint-laundry-bear-zimbra-2026",
          "source_type": "government",
          "published_at": "2026-07-23T00:00:00.000Z",
          "confidence": "high",
          "status": "assessed",
          "notes": "The advisory was authored and co-sealed by intelligence, defence and cybersecurity authorities across multiple NATO partners."
        }
      ],
      "targeting": {
        "regions": [
          "Europe",
          "North America",
          "East Asia",
          "Central Asia"
        ],
        "countries": [
          "Ukraine",
          "Netherlands",
          "NATO member states",
          "European Union member states"
        ],
        "sectors": [
          "Government",
          "Defence",
          "Armed Forces",
          "Aerospace",
          "Transportation",
          "Media",
          "NGOs",
          "Healthcare",
          "Education",
          "Information Technology",
          "Telecommunications",
          "High Technology"
        ],
        "organisations": []
      },
      "campaigns": [
        "laundry-bear-cloud-espionage",
        "laundry-bear-zimbra"
      ],
      "malware": [
        "ulej"
      ],
      "tools": [
        "azurehound",
        "evilginx",
        "flowerbed"
      ],
      "techniques": [
        "password-spraying",
        "valid-accounts",
        "web-session-cookie",
        "adversary-in-the-middle",
        "spearphishing-attachment",
        "phishing",
        "remote-email-collection",
        "email-collection",
        "sharepoint-data",
        "cloud-account-discovery",
        "exploit-client-execution"
      ],
      "vulnerabilities": [
        {
          "cve": "CVE-2025-66376",
          "product": "Zimbra Collaboration Suite",
          "role": "View-based cross-site scripting enabling JavaScript collection and exfiltration from webmail sessions",
          "campaign": "laundry-bear-zimbra",
          "first_observed": "2025-07",
          "confidence": "high",
          "source": "joint-laundry-bear-zimbra-2026",
          "notes": "Exploitation began before the November 2025 patch and January 2026 CVE publication, making it a zero-day when first used."
        }
      ],
      "technique_evidence": [
        {
          "technique": "web-session-cookie",
          "campaign": "laundry-bear-cloud-espionage",
          "first_observed": "2024-09",
          "last_observed": "2025 reporting",
          "confidence": "high",
          "sources": [
            "aivd-mivd-laundry-bear-2025",
            "microsoft-void-blizzard-2025"
          ],
          "notes": "The Dutch police compromise was assessed as pass-the-cookie activity using session material likely obtained through a commodity infostealer ecosystem."
        },
        {
          "technique": "password-spraying",
          "campaign": "laundry-bear-cloud-espionage",
          "first_observed": "2024",
          "last_observed": "2025",
          "confidence": "high",
          "sources": [
            "microsoft-void-blizzard-2025"
          ],
          "notes": "Microsoft describes high-volume but strategically focused identity attacks."
        },
        {
          "technique": "adversary-in-the-middle",
          "campaign": "laundry-bear-cloud-espionage",
          "first_observed": "2025-04",
          "last_observed": "2025-04",
          "confidence": "high",
          "sources": [
            "microsoft-void-blizzard-2025"
          ],
          "notes": "A QR-bearing PDF and typosquatted Microsoft Entra sign-in page were used in a targeted campaign against more than 20 NGOs."
        },
        {
          "technique": "remote-email-collection",
          "campaign": "laundry-bear-cloud-espionage",
          "first_observed": "2024",
          "last_observed": "2025 reporting",
          "confidence": "high",
          "sources": [
            "microsoft-void-blizzard-2025",
            "aivd-mivd-laundry-bear-2025"
          ],
          "notes": "Sources describe rapid bulk collection from Exchange and accessible shared mailboxes."
        },
        {
          "technique": "cloud-account-discovery",
          "campaign": "laundry-bear-cloud-espionage",
          "first_observed": "2024",
          "last_observed": "2025 reporting",
          "confidence": "high",
          "sources": [
            "microsoft-void-blizzard-2025"
          ],
          "notes": "AzureHound appeared in a subset of compromises to enumerate users, roles, groups, applications and devices."
        },
        {
          "technique": "exploit-client-execution",
          "campaign": "laundry-bear-zimbra",
          "first_observed": "2025-07",
          "last_observed": "2026-07 reporting",
          "confidence": "high",
          "sources": [
            "joint-laundry-bear-zimbra-2026"
          ],
          "notes": "Viewing a malicious email in a vulnerable Zimbra web client executed the embedded JavaScript without requiring a link click or attachment open."
        },
        {
          "technique": "email-collection",
          "campaign": "laundry-bear-zimbra",
          "first_observed": "2025-07",
          "last_observed": "2026-07 reporting",
          "confidence": "high",
          "sources": [
            "joint-laundry-bear-zimbra-2026"
          ],
          "notes": "Ulej attempted to collect the last 90 days of email and related account, directory and authentication data."
        }
      ],
      "operational_timeline": [
        {
          "date": "2024-04",
          "title": "Earliest activity in current public reporting",
          "summary": "Microsoft and the Dutch services place the cluster's observed operations from at least 2024 against Western governments and strategically relevant organisations.",
          "confidence": "high",
          "sources": [
            "microsoft-void-blizzard-2025",
            "aivd-mivd-laundry-bear-2025"
          ]
        },
        {
          "date": "2024-09",
          "title": "Dutch police account compromised",
          "summary": "A stolen session cookie provided access to an employee account and the organisation's Global Address List; investigators did not establish theft of other data.",
          "confidence": "high",
          "sources": [
            "aivd-mivd-laundry-bear-2025"
          ]
        },
        {
          "date": "2025-04",
          "title": "Targeted AiTM phishing added to credential acquisition",
          "summary": "Microsoft observed a campaign impersonating a European defence event and using QR-enabled PDF lures, a typosquatted Entra page and Evilginx.",
          "confidence": "high",
          "sources": [
            "microsoft-void-blizzard-2025"
          ]
        },
        {
          "date": "2025-05",
          "title": "Coordinated public disclosure",
          "summary": "Microsoft and the Dutch intelligence services jointly exposed the cluster, its targeting and defensive guidance.",
          "confidence": "high",
          "sources": [
            "microsoft-void-blizzard-2025",
            "aivd-mivd-laundry-bear-2025"
          ]
        },
        {
          "date": "2025-07–2026-07",
          "title": "Zimbra zero-day campaign introduces Ulej and Flowerbed",
          "summary": "A multinational advisory described view-based exploitation of CVE-2025-66376, collection of email and authentication material, and short-lived server infrastructure receiving the stolen data.",
          "confidence": "high",
          "sources": [
            "joint-laundry-bear-zimbra-2026"
          ]
        }
      ],
      "external_identifiers": {
        "mitre_attack": "",
        "other": [
          "Laundry Bear"
        ]
      },
      "related_research": [],
      "sources": [
        "joint-laundry-bear-zimbra-2026",
        "microsoft-void-blizzard-2025",
        "aivd-mivd-laundry-bear-2025"
      ],
      "updates": [
        "void-blizzard-profile-created",
        "void-blizzard-zimbra-campaign-added"
      ],
      "featured": true,
      "url": "https://apt.hecavex.com/actors/void-blizzard/",
      "json_url": "https://apt.hecavex.com/api/actors/void-blizzard.json"
    }
  ]
}