Skip to content
Deep Dive critical GovernmentCritical Infrastructuredefencetelecommunicationsenergy

Cadet Blizzard: GRU Unit 29155 and the Sabotage Doctrine

Executive Summary

Cadet Blizzard is Russia’s GRU Unit 29155, the military intelligence unit historically associated with assassination operations and physical sabotage across Europe. Since at least 2020, the unit has incorporated a dedicated cyber capability that conducts destructive and disruptive operations against Ukraine and NATO member states.

The group is best known for deploying WhisperGate, a destructive wiper disguised as ransomware, against Ukrainian government systems in January 2022 — days before Russia’s full-scale invasion. A September 2024 US Department of Justice indictment named five GRU officers and one civilian co-conspirator, providing the most detailed public accounting of the unit’s leadership and operations to date.

Cadet Blizzard is distinct from Russia’s other GRU-linked cyber actors. It is not a long-term access operator in the mould of APT28 (Unit 26165) or Sandworm (Unit 74455). Its mandate is disruption: destroy data, degrade systems, undermine confidence in institutions, and support physical sabotage operations through intelligence collection and infrastructure degradation. The result is a threat actor with a lower operational tempo than Russia’s espionage-focused units but a significantly higher willingness to cause visible, irreversible harm.

Threat Actor Profile

Microsoft publicly named Cadet Blizzard in June 2023, describing it as a novel GRU-linked cluster distinct from the unit’s better-documented groups. CrowdStrike tracks the same actor as Ember Bear. Other vendor and government designations include DEV-0586 (Microsoft’s earlier designation), UNC2589 (Mandiant), Frozenvista, and UAC-0056. MITRE ATT&CK catalogues the group as G1003.

The GRU designation — Unit 29155, formally the 161st Specialist Training Center — is the important context. This is not a cyber-only unit that happens to be part of the GRU. Unit 29155 is the GRU’s special operations and intelligence directorate responsible for operations that cross state lines: assassinations, sabotage of critical infrastructure, influence campaigns, and unconventional warfare. The cyber capability was added to an existing paramilitary structure.

That origin shapes the doctrine. Cadet Blizzard operations are not collection-focused in the way long-term espionage implants are. They are designed to produce effects: systems offline, data destroyed, public-facing defacements that signal capability and intent.

The unit’s personnel, according to the DOJ indictment, include junior active-duty GRU officers who gain cyber operational experience through live campaigns, alongside more experienced leadership and contracted civilian specialists. This apprenticeship model appears deliberate: it creates a pipeline of operationally seasoned officers while managing exposure of senior personnel.

TTPs and Tradecraft

Initial Access

Cadet Blizzard’s preferred initial access is exploitation of internet-facing services. Their documented vulnerability portfolio includes CVE-2021-26084 (Atlassian Confluence remote code execution) and CVE-2022-41040 combined with ProxyShell exploits against Microsoft Exchange. In addition to unpatched application vulnerabilities, the group targets content management systems and web servers running outdated software at government and critical infrastructure organisations.

The group does not rely heavily on spearphishing for initial access in the same way APT28 does. It is an exploitation-first actor. This makes the exposure of internet-facing unpatched services the primary entry risk, rather than email security or credential-based attacks.

Web Shell Deployment and Persistence

Following initial exploitation, Cadet Blizzard deploys web shells as its primary persistence mechanism. The documented samples are P0wnyshell and reGeorg — both open-source web shells widely used across the threat landscape, offering the advantage of blending into legitimate web administration activity and leaving limited proprietary malware signatures.

Web shells are placed on compromised web servers and provide a persistent foothold that survives system reboots and credential rotation, unless the underlying vulnerability is patched and the shell is specifically identified and removed.

Lateral Movement and Credential Harvesting

From an established web shell, the group uses living-off-the-land techniques and the Impacket toolset for lateral movement. WinPEAS, a privilege escalation discovery tool, has been observed in post-exploitation phases. Credential harvesting from compromised systems enables movement to additional hosts and access to higher-value targets within the network.

Destructive Action

The defining characteristic of Cadet Blizzard operations is the willingness to execute destructive payloads rather than maintaining persistent quiet access. WhisperGate is the most significant documented example.

WhisperGate operates in two stages. The first stage overwrites the master boot record with a ransom-note string that prevents the system from booting. The second stage, a file corruptor disguised as a ransomware encryptor, destroys file contents across specific extensions without any functional decryption capability. The combination is designed to maximise damage to operational systems while maintaining the surface appearance of a financial extortion attack.

The “ransomware” framing was not convincing enough to fool investigators for long, but it served to introduce doubt about attribution in the hours immediately following deployment — a brief but potentially useful window during which targets focused on ransomware response rather than nation-state intrusion response.

Operational Security

CISA and NSA analysis noted that Cadet Blizzard operates seven days per week, with activity concentrated during targets’ off-business hours — a standard nation-state operational security practice that reduces the likelihood of detection and response during initial access and lateral movement phases.

Targeting and Victim Sectors

Cadet Blizzard’s primary targeting is Ukrainian government, military, technology, and telecommunications entities. The unit’s operations in this geography are directly tied to Russia’s military campaign: the January 2022 WhisperGate deployment was part of a broader effort to degrade Ukrainian government systems in the hours before the invasion, alongside kinetic operations.

Beyond Ukraine, the group has conducted extensive reconnaissance and exploitation activity against NATO member states. A joint advisory from the Five Eyes plus NATO allies documented more than 14,000 domain scanning instances targeting organisations across at least 26 NATO member countries and several EU states.

The sectoral targeting in NATO countries maps closely to what is useful for a unit tasked with supporting wartime operations and hybrid warfare: government agencies, military and defence contractors, transportation and logistics, energy infrastructure, and healthcare. These are sectors where operational degradation produces strategic effects.

The US State Department’s $10 million reward offer for information about the indicted officers, posted following the September 2024 charges, signals the level at which the group is assessed as a threat to global critical infrastructure.

Historical Incidents and Impact

WhisperGate — January 2022

The most significant documented operation. In the days immediately before Russia’s full-scale invasion of Ukraine, Cadet Blizzard deployed WhisperGate against multiple Ukrainian government organisations including the Ministry of Foreign Affairs, Ministry of Education, and State Emergency Service. The payload destroyed systems and caused visible outages at a strategically timed moment designed to compound the chaos of imminent invasion.

WhisperGate was notable for being the first documented deployment of a destructive wiper in the Ukraine conflict — preceding by weeks the Hermetic Wiper and CaddyWiper deployments attributed to Sandworm. Microsoft’s initial public disclosure in January 2022 was one of the first attributions of destructive action in the lead-up to the invasion.

Website Defacement Campaign

Alongside the wiper deployment, Cadet Blizzard conducted a campaign of Ukrainian government website defacements, displaying messages claiming that data had been stolen and posted publicly. The defacements were designed for psychological effect — signalling a penetration of government systems to a Ukrainian public already facing imminent military action.

European Reconnaissance and Intrusion

The September 2024 CISA advisory documented that Unit 29155’s cyber operators had conducted reconnaissance against the critical infrastructure of NATO member states and several non-NATO European governments. This activity is assessed as preparatory: building network maps, identifying vulnerabilities, and establishing access that could be activated in the event of escalation.

Physical Sabotage Context

Unit 29155’s cyber operations exist alongside a documented history of physical sabotage. The Vrbétice ammunition depot explosions in the Czech Republic in 2014 — which killed two people and destroyed munitions — were attributed to Unit 29155 by Czech and allied intelligence. The attempted poisoning of Sergei and Yulia Skripal in Salisbury in 2018 was also attributed to the unit’s operatives. European security services have documented a pattern of physical infrastructure sabotage operations across NATO countries since Russia’s 2022 invasion, conducted partly through recruited criminal agents.

The cyber capability is best understood as one layer of a multi-domain sabotage capability, not an isolated technical threat.

Defensive Implications

The Cadet Blizzard threat profile generates several specific defensive recommendations for organisations in targeted sectors.

Patch internet-facing services as a priority. The group’s preferred initial access method is exploitation of unpatched Confluence, Exchange, and web server vulnerabilities. Organisations with internet-facing enterprise applications should treat these as the primary attack surface and ensure patching velocity matches the group’s observed exploitation window.

Audit web-accessible directories for web shells. P0wnyshell and reGeorg are detectable. Regular audits of web server directories for unexpected PHP or ASP files, combined with file integrity monitoring on web root directories, will identify persistence mechanisms that survive credential changes.

Prepare for destructive outcomes, not just data exfiltration. Most incident response plans are built around the assumption that an attacker wants to maintain access and steal data. Cadet Blizzard’s doctrine is different: it is prepared to destroy systems. Offline backups that cannot be reached from a compromised network are not optional for organisations in targeted sectors — they are the recovery mechanism.

Segment operational systems from internet-facing infrastructure. The Cadet Blizzard intrusion chain runs from internet-facing exploitation through web shells into internal networks. Systems that should not be reachable from the internet — operational databases, government records systems, industrial control networks — should be on segments without internet routing.

Monitor for network reconnaissance indicators. The 14,000+ domain scanning instances documented in allied advisories means that many targeted organisations have already been scanned by this group. Network telemetry showing scanning from known malicious infrastructure, or unusual inbound queries against internal systems, should be treated as potential precursors.

Apply the threat model from Ukraine to NATO infrastructure. Cadet Blizzard operated against Ukrainian government infrastructure for months before deploying WhisperGate at a strategically chosen moment. The reconnaissance and access-building phase in NATO countries suggests a similar model. Organisations in targeted sectors should assume they may have been scanned or compromised and conduct threat hunts accordingly, rather than waiting for an active attack to trigger response.