• Also known as UAC-0056, Ember Bear, and Cadet Blizzard.
Nodaria is a Russia-linked threat actor. It has been active since March 2021 and is primarily linked to attacks against Ukraine, including the January 2022 WhisperGate wiper attacks. The group likely also targeted organizations in Georgia and Kyrgyzstan. 
Suspected victims
  • Organizations in Georgia, Kyrgyzstan, and Ukraine
Suspected state sponsor
  • Russian Federation
Type of incident
  • Data destruction
Target category
  • Government
  • Private sector