Dutch intelligence services AIVD and MIVD attributed cyber operations against Dutch targets and other Western governments to the previously unidentified Russian-linked threat actor Laundry Bear. Active since at least 2024, the group has targeted military organizations, government bodies, defense suppliers, civil-society organizations, and digital service providers.
Laundry Bear uses widely available intrusion techniques including password spraying, theft of session cookies, and living-off-the-land activity that abuses legitimate system tools. The agencies urged organizations in the identified sectors—and other potential targets—to apply the mitigations in their joint technical publication and strengthen defenses against credential-based compromise and session hijacking.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
AIVD and MIVD assess that the Russian-linked threat actor Laundry Bear has conducted cyber operations against Western governments since 2024, with particular interest in military organizations, government bodies, defense suppliers, social organizations, and digital service providers.
The Dutch intelligence services published a full report and technical report on Laundry Bear, documenting techniques including password spraying, session-cookie theft, and living-off-the-land activity, and recommending mitigations for affected sectors and other organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.