Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-03

Void Blizzard

Also known as:LAUNDRY BEARUAC-0190

As of 2026-08-02, Void Blizzard is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning vulnerability, apt. Also known as LAUNDRY BEAR, UAC-0190. ATT&CK coverage spans 57 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1566 (Phishing), T1583 (Acquire Infrastructure), T1005 (Data from Local System).

Tracked threats
31 critical · 2 high
First seen
2026-03-17
Last seen
2026-07-29
ATT&CK techniques
57across 3 of 3 threats
Related CVEs
1Referenced by its activity
Attribution
RussiaNation or origin
Nation: Russia · 3 tracked threat(s) · Categories: VULNERABILITY, APT

Activity timeline

Void Blizzard appears in 3 tracked threats between and ; the busiest month was 2026-03 with 1 report.

ATT&CK techniques observed

57 techniques observed across 3 of 3 tracked threats · Collection (7), Credential Access (7), Stealth (formerly Defense Evasion) (7), Command and Control (6), Discovery (6), Resource Development (6)
  • T1566 Phishing — Initial Accessobserved in 3 of 3 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 3 of 3 tracked threats
  • T1005 Data from Local System — Collectionobserved in 2 of 3 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 3 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 3 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 2 of 3 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1098 Account Manipulation — Persistenceobserved in 2 of 3 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 3 tracked threats
  • T1114 Email Collection — Collectionobserved in 2 of 3 tracked threats
  • T1132 Data Encoding — Command and Controlobserved in 2 of 3 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1213 Data from Information Repositories — Collectionobserved in 2 of 3 tracked threats
  • T1539 Steal Web Session Cookie — Credential Accessobserved in 2 of 3 tracked threats

Tracked threats

Related CVEs

1 CVE referenced by tracked Void Blizzard activity