Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Russia-Linked DRILLAPP Backdoor Targets Ukrainian Entities via Microsoft Edge
A new cyberespionage campaign has been identified, targeting Ukrainian organizations with a backdoor named DRILLAPP, attributed to Russian threat actors, specifically the Laundry Bear group. The campaign employs…
3 articles · Updated March 18, 2026 -
US Charges Russian Hacker for Facilitating Void Blizzard Cyber Espionage Campaign
Denis Obrezko, a 36-year-old Russian national, was arrested in Thailand and extradited to the US, where he faces charges for facilitating a cyber espionage campaign linked to the group Void Blizzard. This group has…
8 articles · Updated June 10, 2026 -
Russian Cyber Espionage Suspect Pleads Not Guilty in US Court
Denis Obrezko, a 36-year-old Russian man and former FSB agent, pleaded not guilty to charges related to a cyber espionage campaign targeting Western organizations. Extradited from Thailand, he faces accusations of…
12 articles · Updated July 9, 2026 -
TA488 Exploits Outlook Web Access CVE-2026-42897 in New Campaign
TA488 has launched a campaign exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access (OWA). This vulnerability, disclosed by Microsoft on May 14, 2026, allows attackers to deploy a persistent…
3 articles · Updated July 30, 2026 -
Russian Hackers Target Ukrainian Military with Charity-Themed Malware Campaign
Between October and December 2025, Ukrainian Defense Forces were targeted by a cyberattack disguised as a charitable foundation. The attack, attributed to the Russian group Void Blizzard (Laundry Bear), installed…
3 articles · Updated January 14, 2026 -
Cyberattacks on Ukraine's Defense Forces Linked to Russian Group
CERT-UA reported new cyberattacks involving PLUGGYAPE malware targeting Ukraine’s defense forces. The attacks are attributed with medium confidence to the Russian-linked group Void Blizzard. This incident highlights…
3 articles · Updated January 14, 2026 -
Russian Hacker Denis Obrezko Arrested in Thailand
Denis Obrezko, a 35-year-old Russian man, was arrested on November 6, 2025, in Phuket, Thailand, for alleged cybercrimes linked to the Kremlin. He is reportedly associated with the Void Blizzard group, known for cyber…
17 articles · Updated November 15, 2025 -
Russian Hacker Arrested in Thailand for Cyberattacks on US and Europe
A 35-year-old Russian hacker, Denis Obrezko, was arrested on the Thai island of Phuket for alleged cyberattacks on U.S. and European government agencies. He entered Thailand on October 30 and was taken into custody on…
15 articles · Updated November 22, 2025
Recent Intelligence Reports
- Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover — Csoonline · July 30, 2026
- Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries — Cyberscoop · July 24, 2026
- Russian attackers exploit zero-click vulnerability in Zimbra — Heise.De · July 24, 2026
- Russian spies exploit unpatched Zimbra flaw to steal NATO member emails — Cybernews · July 24, 2026
- Year — Theregister · July 23, 2026
- Zero — Techtimes · July 23, 2026
- Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations — Infosecurity-Magazine · July 23, 2026
- Russian Man Pleads Not Guilty in US Cyber Espionage Case - Global Banking & Finance Review — Globalbankingandfinance · July 9, 2026