U.S. prosecutors charged Russian national Denis Nikolayevich Obrezko with conspiracy to commit unauthorized computer access for allegedly providing infrastructure used by the Kremlin-linked espionage group Void Blizzard, also tracked as Laundry Bear. After his transfer from Thailand to Boston, Obrezko appeared in federal court over accusations that he bought a virtual private server and internet domains through cryptocurrency transactions that enabled intrusions against U.S. and foreign targets. Thai authorities arrested him in Phuket during a joint operation with the FBI and seized laptops, mobile phones, and cryptocurrency wallets.
An unsealed FBI affidavit says investigators confirmed compromises at 11 U.S. companies between June and July 2024, while assessing that the real number of victims is likely higher. Authorities and researchers said Void Blizzard has targeted government, defense, transportation, media, healthcare, educational institutions, NGOs, critical infrastructure, and organizations across Europe, North America, NATO countries, and Ukraine, using stolen credentials, session tokens, VPNs, and U.S.-based proxy services to evade detection. The group has also been linked to spear-phishing with typosquatted Microsoft-themed domains such as miscrsosoft[.]com and micsrosoftonline[.]com, and to theft of Dutch police staff contact information.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Federal prosecutors charged Denis Nikolayevich Obrezko with conspiracy to commit unauthorized computer access for allegedly supporting the Russia-linked threat group Void Blizzard. An unsealed FBI affidavit alleges he bought a virtual private server and domain names used in attacks against U.S. and foreign targets.
After being transferred from Thailand, Denis Obrezko appeared in U.S. federal court in Boston to face charges tied to allegedly supporting Void Blizzard's cyberespionage campaign. Prosecutors said he provided infrastructure including a VPS and internet domain purchased with cryptocurrency.
Thai authorities arrested Russian national Denis Obrezko in Phuket in a joint operation with the FBI. Authorities seized laptops, mobile phones, and cryptocurrency wallets from his hotel room.
An FBI affidavit says investigators verified intrusions at 11 U.S. companies between June and July 2024, attributing the activity to the Russia-aligned threat group Void Blizzard. Investigators assessed that the true number of victims was likely higher and said the campaign also targeted foreign organizations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberscoop.com
Open sourcetherecord.media
Open sourceismg-cdn.nyc3.cdn.digitaloceanspaces.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.