Russian Cyber Espionage Group Laundry Bear Exploits Zero-Day Flaws, Expands Targeting of Finland and NATO Allies, and Demonstrates Evolving Tactics
Finnish and Western intelligence agencies have issued a warning about the heightened activities of Laundry Bear, a Russian state-backed cyber threat actor specializing in espionage. The group has increasingly targeted email systems of organizations in Finland, NATO countries, and Ukraine, exploiting weakened traditional intelligence networks due to expulsions and sanctions. Iltalehti reports that Finnish authorities, including the Security and Intelligence Service (Supo) and military intelligence, have directly responded to Laundry Bear’s operations within Finland, indicating an active and ongoing threat. Yle confirms that Supo has issued multiple recent warnings about cyber espionage efforts from Russia and other authoritarian states, underscoring the persistent nature of the threat. Daily Finland adds that Supo and the Finnish Defence Intelligence (FDI) have issued a renewed warning about Laundry Bear, marking the second such advisory in July, as part of a joint Cybersecurity Advisory (CSA) with the U.S. National Security Agency (NSA) and other Western intelligence services.