US Accuses Russian Cybersecurity Specialist D.O. of Void Blizzard Attacks on European Governments and US Companies, Kaspersky Ties Emerge
American authorities have formally accused Russian information security specialist D.O. of involvement in a series of cyberattacks attributed to the hacking group Void Blizzard, also known as Laundry Bear. The charges, presented in a Boston court, allege that the group has been stealing emails and other communications from government organizations in European countries cooperating with NATO, as well as from at least eleven American companies, beginning in 2023.
D.O. did not enter a guilty plea during the court proceedings. According to information drawn from social media profiles and publicly available resumes, he graduated from the Bauman Moscow State Technical University with a specialization in information security. European journalists have previously described the university as one of the institutions that may train personnel later involved in operations conducted by state structures, although the university itself has not commented on these claims.
The accused previously held a senior position at one of Russia’s largest cybersecurity companies, widely understood to be Kaspersky. The exact nature of his role within the company has not been disclosed. His employment there ended several years before the start of the hacking campaign described by prosecutors. In 2024 the US Department of Commerce prohibited the sale and use of the company’s software in the United States, citing national security threats. European authorities had earlier issued similar risk warnings.
The indictment also connects D.O. to a second IT company based in Nizhny Novgorod, where he served as deputy director starting in 2024. Although the indictment itself does not mention his earlier work at the major cybersecurity firm, this information surfaced later through salary documents and confirmation from a former colleague. The defense attorney declined to discuss the defendant’s employment history.
Specialists observe that transitions between commercial cybersecurity companies and state intelligence structures occur in various countries. Nevertheless, until the court delivers a final ruling, D.O.’s alleged participation in the Void Blizzard operations remains unproven.
Related articles
North Korean WaterPlum Group Infects 30,000 Computers Across 100 Countries via Fake Coding Tests
The North Korean-linked group WaterPlum, also known as Contagious Interview, has infected at least 30,000 computers in more than 100 countries between December 2025 and July 2026. According to the Internet Crime Complaint Center (IC3), the operation moved at least $10.7 million in cryptocurrency to North Korea and compromised more than 7,000 wallets. Attackers pose as recruiters on social media and freelance platforms, luring software developers with nonexistent job offers that require downloading malicious files disguised as coding tests. The malware arsenal includes BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, with the latter hiding inside blockchain-themed projects and abusing Visual Studio Code configurations. Developers are specifically targeted because they often store production keys, wallets, and credentials on the same machines used for testing third-party code. Japanese authorities have dismantled laptop farms connected to the scheme that helped maintain the attackers' operational cover.
US Offers $10 Million Reward for Iranian IRGC Cyber Commander Amir Yaryab
The United States has announced a reward of up to $10 million through the Rewards for Justice program for information leading to the identification or location of Amir Yaryab, leader of the Cyber Operations Command within Iran's Islamic Revolutionary Guard Corps (IRGC). Yaryab oversees units responsible for cyber operations targeting critical infrastructure across the United States, Europe, and the Middle East. Groups under his direction, including Shahid Hemmat and Shahid Shushtari, have conducted campaigns against defense, energy, telecommunications, finance, transportation, hotels, and airlines sectors. He is also linked to structures associated with the CyberAv3ngers group, known for attacks on industrial control systems and operational technology equipment. Previous operations attributed to IRGC-linked actors compromised internet-exposed Unitronics programmable logic controllers, affecting at least 75 devices between November 2023 and January 2024, including 34 in the US water and wastewater sector. The reward specifically targets individuals acting under foreign government direction in malicious cyber activities against US critical infrastructure.
APT28 Expands Espionage with New HOOKEDGE Backdoor Targeting European Organizations
The Russian-linked APT28 group, also known as BlueDelta, has deployed a new lightweight backdoor called HOOKEDGE as part of a cyber-espionage campaign against strategic European entities. The attacks, assessed with moderate confidence, targeted government, diplomatic, and defense manufacturing organizations in Romania, Spain, and Turkey between September 2025 and April 2026. Infection begins with spear-phishing emails delivering Microsoft Word documents containing malicious macros that mimic official Spanish government materials. Upon execution, the macros drop files, establish persistence via scheduled tasks, and deploy the HOOKEDGE backdoor written in batch scripts. The malware uses hidden Microsoft Edge instances and the legitimate webhook.site service to blend command-and-control traffic with normal web activity. In high-value victims, operators installed a second HOOKEDGE instance with five-minute check-ins for faster control and data collection. The backdoor shows strong code similarities to the older HEADLACE implant previously attributed to the same group.
Iran-Linked Cyber Attack Leaves Small UK Power Plant Offline for Four Days
A cyber attack attributed to hackers with suspected ties to Iran took a small-scale UK power generation facility offline for approximately four days in July 2026. The incident affected a roughly 15 MW generator used to support peak demand periods, yet caused no customer outages or disruption to the national electricity grid. British authorities have not issued an official attribution, and investigators have not publicly identified the malware, vulnerability, or initial access vector used in the operation. Recovery required four days of extensive validation across controllers, configurations, security systems, and remote access points to ensure no residual risks remained. The case highlights the operational challenges of restoring industrial control environments after suspected nation-state activity. In response, UK authorities have strengthened guidance for the energy sector and are considering additional protective measures for critical infrastructure suppliers.