Cadet Blizzard
Russian state-sponsored (GRU Unit 29155) · Destructive sabotage / disruption across NATO member states and Ukraine / influence operations
Tactics, Techniques & Procedures (TTPs)
- WhisperGate wiper deployment — destructive malware disguised as ransomware, designed to permanently destroy data without recovery capability
- Web defacement campaigns against Ukrainian government websites as information operation accompaniment to wiper deployment
- Credential theft via spear-phishing and credential-harvesting infrastructure
- Physical sabotage coordination: Unit 29155 combines cyber operations with in-person sabotage and arson campaigns across NATO member states
- Targeting of critical infrastructure for pre-conflict disruption: IT systems, energy, water, transportation
- N-day exploitation of internet-facing systems for initial access to government and contractor networks
- Compromised infrastructure as staging platform for wiper and destructive payload delivery
Known Targets
Analyst Notes
Publicly attributed to GRU Unit 29155 by a CISA-led joint advisory (AA24-249A) in September 2024, with six officers named and US DOJ indictments issued. Unit 29155 is the GRU directorate historically associated with physical assassination and sabotage operations — Salisbury poisoning (2018), Bulgaria assassination plots. The cyber component of its mandate emerged publicly with WhisperGate in January 2022, deployed against Ukrainian government systems one month before the full-scale invasion. Unlike Sandworm (Unit 74455), which focuses on destructive OT/ICS attacks, Cadet Blizzard targets IT systems and government administration. Since 2024, the unit has been linked to a pattern of physical sabotage across NATO states: arson attacks on logistics facilities, infrastructure damage, and assassination plot disruptions — cyber operations are one tool among several. US DOJ offered $10 million for information leading to officer identification.
Also Known As