Laundry Bear is a Russian state-supported cyberespionage actor active against Western government and commercial organizations since at least 2024. It is also tracked as Void Blizzard, TA488, UAC-0190, CL-STA-1114, and formerly UNK_PitStop. The group has been characterized as aligned with, and operating in support of, Russian intelligence interests. Laundry Bear targets government and military-related organizations, defense suppliers, critical-sector entities, digital service providers, telecommunications, financial services, energy, aerospace, education, civil-society organizations, and technology organizations. Confirmed targeting has included Ukrainian government entities and U.S. government, defense-industrial, nuclear, research, and commercial organizations. The actor conducts credential phishing, password spraying, session-cookie theft, and replay of stolen cloud-session tokens, often using geographically proximate proxy infrastructure to evade location-based access controls. It has also used view-based or "half-click" exploitation of webmail vulnerabilities: malicious emails execute code when opened in vulnerable Zimbra Collaboration Suite or on-premises Microsoft Exchange Outlook Web Access sessions. These operations used the ZimReaper and OWAReaper browser-resident JavaScript implants to collect credentials, authentication tokens, mailbox contents, contacts, directories, and configuration data. Laundry Bear has established persistence through application passwords, browser-resident storage, cached webmail content, OAuth-token abuse, and server-side mailbox-folder permission changes. Its implants have used web-based command channels, inbound email, HTTPS traffic relayed through legitimate services, and DNS tunneling for command-and-control and data exfiltration. The group also employs living-off-the-land techniques and removes or modifies malicious email artifacts to reduce detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Initially targeting a vulnerability tracked as CVE-2025-66376, the group later adapted its techniques to exploit a second vulnerability in Outlook Web Access.
CVE-2026-42897 is a high-severity stored cross-site scripting vulnerability affecting on-premises Microsoft Exchange Server Outlook Web Access (OWA). It is described as actively exploited by TA488 through crafted HTML email that executes JavaScript when opened in OWA.
220 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting zero-click email espionage campaigns that exploit webmail vulnerabilities to steal email correspondence, session tokens, and credentials from critical-sector organizations.
Conducting zero-click or 'half-click' email espionage campaigns by exploiting webmail vulnerabilities in Zimbra Collaboration Suite and later Outlook Web Access to steal email, session tokens, saved credentials, and OAuth tokens from organizations in critical sectors.
Referenced as a Russia-linked APT group that exploited a Zimbra XSS vulnerability in a prior campaign.
Phishing campaign targeting Zimbra mail servers at Western government and commercial organizations, using a Zimbra stored XSS flaw to deploy a malicious JavaScript payload for email and sensitive data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.