Cadet Blizzard is a Russia-linked threat actor associated with GRU Unit 29155, also known as the 161st Specialist Training Centre. The group has been tracked under multiple aliases including Ember Bear, Saint Bear, DEV-0586, Bleeding Bear, Lorec53, Storm-0587, TA471, UAC-0056, and UNC2589. It is assessed as part of the Russian state cyber apparatus and has been linked to disruptive and destructive operations aligned with Russian military and hybrid objectives, particularly against Ukraine. Cadet Blizzard is notable for combining espionage, phishing, and destructive activity. The actor has been associated with the January 2022 WhisperGate operation against Ukrainian government organizations, a multi-stage wiper campaign disguised as ransomware and intended to render systems inoperable rather than generate profit. The group has also been linked to intrusion activity against Estonian government entities involving data exfiltration. Reporting on Unit 29155 indicates an evolution from a unit historically known for sabotage and covert physical operations into one conducting cyber operations that support broader Russian state objectives. The actor’s targeting has included government and related entities, especially in Ukraine and Europe. Social engineering and impersonation are recurring features of its operations. Cadet Blizzard has impersonated government-associated organizations in phishing campaigns and has used malicious websites and links designed to mimic legitimate resources. The group has relied on user interaction for execution, including malicious attachments and similar lures. Observed tradecraft includes extensive use of Windows-native tooling and scripting, especially PowerShell and Windows Script Host. Cadet Blizzard has used PowerShell for execution and system reconnaissance, including gathering information from compromised systems such as email servers. It has also used wscript to execute intermediate payloads. Defense evasion is a prominent characteristic: the actor has modified Windows Defender settings through registry changes, altered scheduled tasks and registry entries associated with Defender, and used tooling to stop Defender services and weaken protections. Registry modification has also been used for anti-forensics and broader evasion purposes. Cadet Blizzard has demonstrated collection and staging behaviors beyond destructive attacks. It has engaged in mass collection from compromised systems, exfiltrated imagery from compromised IP cameras, and used legitimate online services to host or stage malicious content. The actor has also been reported to acquire malware and related tooling from dark web forums, indicating a willingness to combine bespoke operations with externally sourced capabilities. Across aliases such as Ember Bear and Saint Bear, the group’s activity spans credential access, remote services abuse, command and scripting interpreter use, proxying, defense impairment, and destructive malware deployment. Overall, Cadet Blizzard represents a Russian military intelligence threat actor focused on disruptive, destructive, and intelligence-supporting cyber operations in service of state objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
...has exploited Office vulnerabilities such as CVE-2017-11882...
BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access... Magic Hound has exploited ... on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207)... Ember Bear ... CVE-2022-41040, ProxyShell, and other vulnerabilities in Microsoft Exchange.
Ember Bear ... CVE-2022-41040 ... in Microsoft Exchange... Play ... CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as Eternal Blue, during operations.
7 more CVEs tied to this actor tracked in Mallory.
279 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with sabotage support, destructive activity, espionage, and wartime support operations connected to Ukraine and regional military objectives.
Listed in annotations associated with the credential-access technique.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Referenced as a threat actor associated with the MITRE ATT&CK technique T1090.003 (Multi-hop Proxy) in the detection annotation for access to anonymizer services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.