US Accuses Russian Cybersecurity Specialist D.O. of Void Blizzard Attacks on European Governments and US Companies, Kaspersky Ties Emerge
American authorities have formally accused Russian information security specialist D.O. of involvement in a series of cyberattacks attributed to the hacking group Void Blizzard, also known as Laundry Bear. The charges, presented in a Boston court, allege that the group has been stealing emails and other communications from government organizations in European countries cooperating with NATO, as well as from at least eleven American companies, beginning in 2023.
D.O. did not enter a guilty plea during the court proceedings. According to information drawn from social media profiles and publicly available resumes, he graduated from the Bauman Moscow State Technical University with a specialization in information security. European journalists have previously described the university as one of the institutions that may train personnel later involved in operations conducted by state structures, although the university itself has not commented on these claims.
The accused previously held a senior position at one of Russia’s largest cybersecurity companies, widely understood to be Kaspersky. The exact nature of his role within the company has not been disclosed. His employment there ended several years before the start of the hacking campaign described by prosecutors. In 2024 the US Department of Commerce prohibited the sale and use of the company’s software in the United States, citing national security threats. European authorities had earlier issued similar risk warnings.
The indictment also connects D.O. to a second IT company based in Nizhny Novgorod, where he served as deputy director starting in 2024. Although the indictment itself does not mention his earlier work at the major cybersecurity firm, this information surfaced later through salary documents and confirmation from a former colleague. The defense attorney declined to discuss the defendant’s employment history.
Specialists observe that transitions between commercial cybersecurity companies and state intelligence structures occur in various countries. Nevertheless, until the court delivers a final ruling, D.O.’s alleged participation in the Void Blizzard operations remains unproven.
Related articles
Russian State-Supported Group LAUNDRY BEAR Exploits Zero-Day CVE-2025-66376 in Zimbra Collaboration Suite
Synacor’s Zimbra Collaboration Suite was targeted in a zero-day campaign by the Russian state-backed threat actor known as LAUNDRY BEAR. The stored cross-site scripting flaw in the webmail stylesheet handler allowed attackers to steal past emails simply by having victims view a specially crafted HTML message. No user interaction beyond opening the email was required for JavaScript execution in the browser. On 23 July 2026, sixteen countries including the United States, European nations and Australia issued a joint advisory signed by twenty-seven agencies such as NSA, FBI and CISA. The vulnerability received CVE-2025-66376 and a CVSS v3.1 base score of 7.2, rated High. Analysts assess the campaign focused on intelligence collection against Western government and corporate targets.
Russian Intelligence Hijacks Exposed Security Cameras in Europe and Ukraine for Military Surveillance
Dutch intelligence agencies AIVD and MIVD have revealed that Russian military intelligence is systematically compromising internet-connected security cameras across Europe and Ukraine. The attackers scan for exposed devices using brand fingerprints, then log in with default passwords and outdated firmware without needing zero-day exploits. In Ukraine, live camera feeds are used not only for reconnaissance of military transport routes and weapon deliveries but also to directly support targeting of Ukrainian forces and equipment. Censys identified over 87,000 vulnerable cameras in the EU, NATO countries, and Ukraine, with more than 4,000 located in Ukraine alone. While the actual number of confirmed compromises is smaller, the cameras are strategically positioned along key military logistics routes. The agencies issued basic but critical recommendations including disabling public exposure, changing default credentials, and applying patches for known vulnerabilities such as CVE-2016-7407 and CVE-2021-39275.
Iranian State-Sponsored Hackers Unveil Cavern C2 Framework: Multi-Format .NET Compilation Bypasses All Security Detection Tools
In July 2026, Check Point Research exposed Cavern Manticore, an Iranian MOIS-linked APT group, actively targeting Israeli IT providers and government entities with a sophisticated modular C2 framework called Cavern (also known as Cav3rn). Unlike previous Iranian groups that rely on public tools, this actor built an entirely custom .NET-based framework deliberately compiled into three incompatible binary formats—pure IL, mixed-mode C++/CLI, and .NET 8 Native AOT—to force analysts to maintain multiple reverse-engineering toolchains and dramatically increase operational costs. The framework achieves near-zero detection rates on VirusTotal by avoiding traditional obfuscation and instead weaponizing compilation formats themselves, with modules running in isolated AppDomains that leave no persistent artifacts. Attackers gain initial access through compromised RMM solutions such as SysAid, abusing legitimate update mechanisms to sideload the Cavern Agent disguised as uxtheme.dll via a WinDirStat DLL side-loading chain. Communication uses XOR encryption with Base64 encoding, fixed Edge User-Agent strings, custom headers, and a unique protocol syntax, while supporting hot updates and aggressive cleanup. The campaign coincides with parallel operations by MuddyWater against regional targets, highlighting Iran’s coordinated escalation in cyberspace and the growing threat of supply-chain trust abuse against MSPs and RMM platforms worldwide.
NSA Revives Elite TAO Hacking Unit Behind Stuxnet and WannaCry to Accelerate Cyber Operations Against China and Adversaries
The U.S. National Security Agency has restored the original name Tailored Access Operations (TAO) to its premier cyber intrusion division as part of a major internal restructuring aimed at speeding up offensive operations against hostile nations, including China. The unit, which operated under the name Office of Computer Network Operations (CNO) following the 2016 NSA21 reforms, will once again function as a distinct entity with its own dedicated building at Fort Meade. The change reverses aspects of the earlier reorganization that had merged offensive operations and intelligence collection into larger directorates, a move former employees say hindered collaboration between developers and operators. Deputy NSA Director Tim Kosiba, a former TAO member, oversaw the revival, which was presented to Defense Secretary Pete Hegseth during his visit to the agency’s headquarters. TAO has long been linked to some of the most sophisticated U.S. cyber tools, including those used in the Stuxnet operation against Iran’s nuclear program and the EternalBlue exploit later deployed in the global WannaCry ransomware attack. The unit develops custom malware, persistence mechanisms, and covert access tools for intelligence collection against foreign targets. Former personnel believe the restored structure will improve attack preparation and innovation, particularly in the era of artificial intelligence.