Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Affidavit in Support of Application for Criminal Complaint

0
Medium
Published: 06/11/2026 (06/11/2026, 21:09:37 UTC)
Source: AlienVault OTX General

Description

An FBI investigation identified Denis Nikolayevich Obrezko, a Russian national, as facilitating cyber intrusions conducted by the Russia-aligned threat group Void Blizzard. Between June and July 2024, multiple U.S. companies across various sectors were targeted in a large-scale cyber espionage campaign involving mass email harvesting and unauthorized access. The threat actors utilized stolen session tokens, proxy services, and VPNs to authenticate to victim Office 365 environments and exfiltrate data. Obrezko allegedly obtained critical infrastructure including a virtual private server and domain registration used in these attacks. FBI investigation linked Obrezko through cryptocurrency transactions, email accounts, phone numbers, and IP addresses to domains and infrastructure used in the intrusion campaign. Eleven U.S. companies have confirmed unauthorized access, representing only a fraction of suspected victims nationwide.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/15/2026, 20:31:12 UTC

Technical Analysis

The FBI investigation uncovered that Denis Nikolayevich Obrezko facilitated cyber intrusions by the Russia-aligned threat group Void Blizzard. The group targeted multiple U.S. companies across sectors in a cyber espionage campaign involving mass email harvesting and unauthorized access to Office 365 environments. Attackers used stolen session tokens combined with proxy and VPN infrastructure to authenticate and exfiltrate data. Obrezko was linked to the campaign through cryptocurrency transactions, email accounts, phone numbers, and IP addresses associated with the malicious infrastructure. Eleven companies confirmed breaches, indicating a widespread campaign.

Potential Impact

Unauthorized access to Office 365 environments allowed the threat actors to exfiltrate sensitive data from multiple U.S. companies. The use of stolen session tokens and proxy infrastructure enabled stealthy authentication and data theft. The campaign represents a significant espionage threat to U.S. corporate and critical infrastructure sectors, with confirmed breaches in at least eleven companies and likely many more affected.

Mitigation Recommendations

No specific patch or remediation is available as this is a campaign leveraging stolen credentials and infrastructure. Organizations should review and strengthen their Office 365 session management and authentication controls, including monitoring for unusual session token usage and implementing multi-factor authentication. Since this is not a cloud service vulnerability, remediation depends on organizational security controls. Patch status is not yet confirmed — check vendor advisories for any updates related to Office 365 security.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://cyberscoop.com/wp-content/uploads/sites/3/2026/06/11-1.pdf"]
Adversary
Void Blizzard
Pulse Id
6a2b2411d3d3323a465da4c0
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainlnstagram.com
domainebsummlt.eu
domainmiscrsosoft.com
domainffice365.com
domainmicsroft.com

Ip

ValueDescriptionCopy
ip172.86.75.235

Url

ValueDescriptionCopy
urlhttp://lnstagram.com/wlsperrrrr/

Threat ID: 6a3052ca0b89be688882696a

Added to database: 06/15/2026, 19:30:18 UTC

Last enriched: 06/15/2026, 20:31:12 UTC

Last updated: 07/31/2026, 07:13:31 UTC

Views: 90

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses