Skip to content
← All Threat Actors
Nation-State critical Russia

Cadet Blizzard

Russian state-sponsored (GRU Unit 29155) · Destructive sabotage / disruption across NATO member states and Ukraine / influence operations

Reports 1
Active Since 2020
Last Reported 2 Jul 2026
Sectors Targeted government, critical-infrastructure, defence, telecommunications, energy

Tactics, Techniques & Procedures (TTPs)

  • WhisperGate wiper deployment — destructive malware disguised as ransomware, designed to permanently destroy data without recovery capability
  • Web defacement campaigns against Ukrainian government websites as information operation accompaniment to wiper deployment
  • Credential theft via spear-phishing and credential-harvesting infrastructure
  • Physical sabotage coordination: Unit 29155 combines cyber operations with in-person sabotage and arson campaigns across NATO member states
  • Targeting of critical infrastructure for pre-conflict disruption: IT systems, energy, water, transportation
  • N-day exploitation of internet-facing systems for initial access to government and contractor networks
  • Compromised infrastructure as staging platform for wiper and destructive payload delivery

Known Targets

Ukrainian government ministries and agencies (pre-invasion, January 2022)NATO member state government and defence organisationsEuropean critical infrastructure (energy, transportation)IT service providers with government contractsDefence contractors in Poland, Czech Republic, Germany, and Baltic states

Analyst Notes

Publicly attributed to GRU Unit 29155 by a CISA-led joint advisory (AA24-249A) in September 2024, with six officers named and US DOJ indictments issued. Unit 29155 is the GRU directorate historically associated with physical assassination and sabotage operations — Salisbury poisoning (2018), Bulgaria assassination plots. The cyber component of its mandate emerged publicly with WhisperGate in January 2022, deployed against Ukrainian government systems one month before the full-scale invasion. Unlike Sandworm (Unit 74455), which focuses on destructive OT/ICS attacks, Cadet Blizzard targets IT systems and government administration. Since 2024, the unit has been linked to a pattern of physical sabotage across NATO states: arson attacks on logistics facilities, infrastructure damage, and assassination plot disruptions — cyber operations are one tool among several. US DOJ offered $10 million for information leading to officer identification.

Also Known As

Ember Bear (CrowdStrike)DEV-0586 (Microsoft legacy)UAC-0056FrozenvistaSaint Bear