Netherlands' intelligence agencies have disclosed the existence of a new Russian threat actor, which they named Laundry Bear, that has quietly breached Western government organizations using deceptively simple techniques.
The Netherlands General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD) have revealed, in a jointly published the operations of a previously unknown Russian state-supported cyber actor.
The authorities have dubbed the group Laundry Bear. It's been conducting espionage campaigns since 2024 against NATO and EU government institutions, defense contractors, and many other organizations.
"Laundry Bear flies under the radar using living-off-the-land methods that evade detection," the report states. "Its attacks have a high success rate compared to other Russian threat actors."
Laundry Bear first came to the attention of authorities after a cyberattack on the Dutch police in September 2024. They used a method known as a pass-the-cookie attack, which gave access to employee accounts and exfiltrated the Global Address List (GAL), which is a directory containing the contact information of all Dutch police staff.
Investigators say that the access cookie was stolen with the help of an infostealer malware and later purchased by Laundry Bear on the dark net.
Unlike ransomware gangs, Laundry Bear's motives seem to be purely espionage-driven. The group goes after email accounts, cloud storage, and access privileges to extract sensitive data. Some of the targeted areas include:
"The actor has a surprising level of understanding of Western military production and procurement," analysts wrote. "It seeks technologies Russia struggles to acquire due to sanctions."
Laundry Bear uses a mix of stealthy tactics to infiltrate systems and extract valuable information:
Laundry Bear's methods, like password spraying, web session cookie theft, and remote email scraping, overlap with those used by APT28, another Russian GRU-affiliated group also known as Fancy Bear. However, Dutch services believe that Laundry Bear is a separate entity.
tags
Silviu is a seasoned writer who followed the technology world for almost two decades, covering topics ranging from software to hardware and everything in between.
View all postsMay 23, 2025
May 16, 2025
April 03, 2025
March 12, 2025