New publication. Cadet Blizzard.
Cadet Blizzard: When Cyber Espionage Becomes Cyber Sabotage
Some threat actors steal information. Others are built to disrupt, destroy, and support broader military objectives.
Cadet Blizzard (also tracked as Ember Bear and DEV-0586) belongs to the latter category. Widely linked by leading cybersecurity organisations to GRU Unit 29155, the group has become one of the key Russian cyber actors targeting Ukraine, NATO members, and organisations supporting Ukraine.
Its activity extends far beyond traditional cyber espionage. Cadet Blizzard combines phishing, credential theft, destructive malware, supply-chain targeting, and information operations into coordinated campaigns designed to achieve strategic rather than purely technical objectives.
The group gained international attention through the deployment of WhisperGate in January 2022. Although the malware presented itself as ransomware, its real purpose was data destruction and operational disruption, making it one of the clearest examples of a wiper disguised as ransomware.
This report examines the evolution of Cadet Blizzard from its early activity through recent campaigns, analysing attribution, operational structure, targeting priorities, infrastructure, and MITRE ATT&CK techniques. It also explores how destructive malware, long-term network access, and psychological impact are integrated into a broader model of hybrid cyber operations.
Understanding groups like Cadet Blizzard is essential for anyone analysing modern state-sponsored cyber threats. Their operations demonstrate that today’s cyber campaigns are no longer limited to intelligence collection—they increasingly combine espionage, sabotage, and information influence within a single operational framework.