Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

Russian State-Sponsored Hackers Exploit Zimbra Zero-Day in Sophisticated Phishing Campaign

A highly sophisticated phishing campaign has been uncovered, targeting Western governments and enterprises through a vulnerability in the popular email management system, Zimbra Collaboration Suite (ZCS). The attack, attributed to a Russian state-sponsored threat group dubbed “Laundry Bear,” has compromised networks of US and Ukrainian organizations, raising concerns about the potential for sensitive information to be gathered by the attackers.

The campaign began in July 2025, using a zero-day vulnerability in ZCS tracked as CVE-2025-66376. This exploit allowed Laundry Bear to send “half-click” phishing emails that required only a victim to open or preview the message, rather than clicking on a link or opening a malicious attachment. The vulnerability was patched by Zimbra in November 2025, but it’s unclear why the company didn’t disclose the flaw until weeks later.

The attack appears to be designed specifically to gather sensitive information for the Russian Federation. According to intelligence and cybersecurity agencies from over a dozen countries, the Laundry Bear threat group has been targeting ZCS customers since at least July 2025. This is not an isolated incident – it’s part of a larger trend of Russian state-sponsored hackers exploiting vulnerabilities in popular software systems.

Laundry Bear’s tactics have evolved significantly over time. Initially, they relied on unsophisticated techniques such as password spraying and conventional phishing attacks. However, last year they began using the “novel exploit” for CVE-2025-66376, which allows them to craft “half-click” phishing emails that only require a victim to open or preview the message.

The Joint Advisory issued by the US government and several allied nations warns of the potential consequences of this attack. The advisory states that Laundry Bear’s campaign is designed to gather sensitive information for the Russian Federation, and that the threat group has been active since at least July 2025.

What makes this attack particularly concerning is its sophistication and stealth. Unlike traditional phishing campaigns, which require a victim to click on a link or open a malicious attachment, Laundry Bear’s “half-click” exploit can breach Zimbra webmail servers simply by requiring a user to view a malicious email within a vulnerable version of the webmail service.

The bottom line is that this attack highlights the importance of staying vigilant and up-to-date with security patches. It also underscores the need for organizations to be aware of the potential risks associated with using popular software systems, especially when it comes to zero-day vulnerabilities. To protect yourself and your organization, ensure you’re running the latest version of Zimbra and are monitoring your email system closely for any suspicious activity.


Source: Dark Reading — 2026-07-23