Laundry Bear — APT Profile

Laundry Bear is a Russia-affiliated cyber-espionage actor publicly named by the Dutch General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) in a joint 27 May 2025 advisory, following investigation of a 23 September 2024 breach of the Dutch national police in which employee contact data was pulled from the Global Address List via a pass-the-cookie attack using a session cookie the actor is believed to have bought on a criminal marketplace. Microsoft independently tracks the same cluster as Void Blizzard, assessed with high confidence to be Russia-affiliated and active since at least April 2024. The group relies on largely living-off-the-land tradecraft with no observed custom malware, combining password spraying and purchased infostealer session cookies with, since April 2025, Evilginx adversary-in-the-middle phishing to obtain Exchange/Entra credentials, then abuses Exchange Online, Outlook Web Access, and Microsoft Graph APIs to bulk-collect mailboxes, files, and Teams data. Targeting concentrates on EU and NATO government, defense, and defense-contractor organizations, with a stated interest in Western military-equipment procurement and arms deliveries to Ukraine, alongside IT/digital-service providers, critical infrastructure, education, NGOs, and media. Dutch intelligence describes the group as unusually fast-paced and automated with a high compromise success rate, and notes tradecraft overlap with APT28 while assessing the two as distinct actors.

Also tracked as

Void Blizzard, UAC-0190, TA488

IntelFusions coverage (2)

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions