Microsoft has revealed a hitherto unreported cluster of malicious behavior that it claims is related to global cloud exploitation and comes from a threat actor with ties to Russia called Void Blizzard (also known as Laundry Bear).
The hacking group, which has been active since at least April 2024, is associated with espionage activities that primarily target organizations that are crucial to Russian government goals, such as those in the European and North American government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors.
According to a report released today by the Microsoft Threat Intelligence team, they frequently use stolen sign-in credentials that they most likely purchase from online marketplaces to enter companies. They steal a lot of data and emails once they’re inside.
It has been discovered that Void Blizzard’s attacks disproportionately target Ukraine and NATO members read more about Russian Hackers Breach 20+ NGOs Using Evilginx Phishing via Fake Microsoft Entra Pages.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
