securitylab_nJuly 17, 2026🇷🇺Translated from Russian

US Accuses Russian Cybersecurity Specialist D.O. of Void Blizzard Attacks on European Governments and US Companies, Kaspersky Ties Emerge

American authorities have formally accused Russian information security specialist D.O. of involvement in a series of cyberattacks attributed to the hacking group Void Blizzard, also known as Laundry Bear. The charges, presented in a Boston court, allege that the group has been stealing emails and other communications from government organizations in European countries cooperating with NATO, as well as from at least eleven American companies, beginning in 2023.

D.O. did not enter a guilty plea during the court proceedings. According to information drawn from social media profiles and publicly available resumes, he graduated from the Bauman Moscow State Technical University with a specialization in information security. European journalists have previously described the university as one of the institutions that may train personnel later involved in operations conducted by state structures, although the university itself has not commented on these claims.

The accused previously held a senior position at one of Russia’s largest cybersecurity companies, widely understood to be Kaspersky. The exact nature of his role within the company has not been disclosed. His employment there ended several years before the start of the hacking campaign described by prosecutors. In 2024 the US Department of Commerce prohibited the sale and use of the company’s software in the United States, citing national security threats. European authorities had earlier issued similar risk warnings.

The indictment also connects D.O. to a second IT company based in Nizhny Novgorod, where he served as deputy director starting in 2024. Although the indictment itself does not mention his earlier work at the major cybersecurity firm, this information surfaced later through salary documents and confirmation from a former colleague. The defense attorney declined to discuss the defendant’s employment history.

Specialists observe that transitions between commercial cybersecurity companies and state intelligence structures occur in various countries. Nevertheless, until the court delivers a final ruling, D.O.’s alleged participation in the Void Blizzard operations remains unproven.

Related articles

AntiMalwareState-Sponsored & APT

HoneyMyte APT Deploys Kernel-Level CoolClient Backdoor Disguised as Microsoft Defender

The Chinese-speaking APT group HoneyMyte has deployed an updated version of its CoolClient backdoor in espionage operations targeting government and private organizations in Russia, Myanmar, Mongolia, Pakistan, and India. The new variant operates at the Windows kernel level using a signed driver, allowing it to hide processes, files, registry entries, and network activity while evading detection. Attackers first abuse PlugX to add exclusions for Microsoft Defender, then drop a fake Windows Defender directory containing the renamed Sangfor binary defender.exe and the malicious libngs.dll. A scheduled task ensures persistence by launching the fake defender.exe with high privileges on system startup. Kaspersky GReAT researchers note that the kernel-mode capabilities significantly increase the backdoor’s stealth and survivability compared to its previous user-mode implementation. The campaign demonstrates sophisticated living-off-the-land techniques combined with legitimate software abuse.

BoletimSecState-Sponsored & APT

Lazarus Group Exploits Windows Kernel Zero-Day CVE-2026-68820 to Deploy FudModule Rootkit

The North Korean Lazarus APT group has been actively exploiting a zero-day vulnerability in the Windows kernel to escalate privileges to SYSTEM level and install the FudModule rootkit. The flaw, tracked as CVE-2026-68820, resides in the afd.sys driver responsible for network functions and socket management. Microsoft released a patch for the issue on August 11. The attacks form part of the ongoing Operation Dream Job campaign, which uses fake job offers to target professionals in defense, aerospace, and aviation sectors. Victims in Brazil, Europe, and India are tricked into opening malicious PDF viewers or prepared files that deliver the MISTPEN downloader. Once initial access is obtained, the zero-day exploit elevates privileges, allowing FudModule to tamper with Windows telemetry and weaken EDR solutions as well as Smart App Control.

BoletimSecState-Sponsored & APT

Iranian Hackers Disable Safety Alarms in US Industrial Control Systems

Iranian threat actors have been compromising internet-exposed industrial controllers across the United States since at least March 2026, modifying alarm and safety shutdown logic in critical infrastructure. The campaign has targeted government organizations and operators in the water, wastewater, and energy sectors, resulting in operational disruptions and financial losses. Attackers focus on devices with insecure remote access, weak credentials, or default configurations rather than exploiting zero-day vulnerabilities. Targeted hardware includes Rockwell CompactLogix and Micro850 controllers, Schneider BMX P34 and Modicon M340 PLCs, and Siemens S7-1200 models. Operators use rented foreign infrastructure and legitimate programming software to download, alter, and re-upload control logic projects. In at least one case, malicious code maintained normal operations while introducing instructions that bypassed safe operational limits and altered data displayed on HMI and SCADA interfaces. The tactics closely resemble prior activity attributed to the CyberAv3ngers group linked to Iran’s Islamic Revolutionary Guard Corps, though direct attribution remains unconfirmed.

Security NEXTState-Sponsored & APT

Russian State-Supported Group LAUNDRY BEAR Exploits Zero-Day CVE-2025-66376 in Zimbra Collaboration Suite

Synacor’s Zimbra Collaboration Suite was targeted in a zero-day campaign by the Russian state-backed threat actor known as LAUNDRY BEAR. The stored cross-site scripting flaw in the webmail stylesheet handler allowed attackers to steal past emails simply by having victims view a specially crafted HTML message. No user interaction beyond opening the email was required for JavaScript execution in the browser. On 23 July 2026, sixteen countries including the United States, European nations and Australia issued a joint advisory signed by twenty-seven agencies such as NSA, FBI and CISA. The vulnerability received CVE-2025-66376 and a CVSS v3.1 base score of 7.2, rated High. Analysts assess the campaign focused on intelligence collection against Western government and corporate targets.