Laundry Bear
Coverage of Laundry Bear in the Nexus archive.
- Laundry Bear’s webmail hackers had more in store after February, report says
Researchers report that the Russian state-linked hacking group Laundry Bear began exploiting a vulnerability in Microsoft Outlook Web Access and had further plans after February.
- Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
A Russian state-sponsored threat group, Laundry Bear (also known as Void Blizzard), has been exploiting a zero-day vulnerability in Zimbra Collaboration Suite since July 2025 to steal sensitive data from governments and organizations in sectors like defense, education, and technology. The exploit, patched in November 2025, allows attackers to steal emails, passwords, and other data without user interaction, as reported in a joint cybersecurity advisory by U.S. authorities and international partners.
- Russian national charged in connection with Void Blizzard espionage campaign
A Russian national, Denis Nikolayevich Obrezko, has been charged by U.S. federal prosecutors for conspiracy to commit unauthorized computer access linked to the Void Blizzard cyber-espionage campaign. The group, also tracked as Laundry Bear, is accused of using stolen session tokens and proxy services to infiltrate systems of businesses, educational institutions, and government agencies in multiple countries.