Russian hackers have been exploiting a zero-click vulnerability in Zimbra Collaboration email servers to steal sensitive information from organizations worldwide. The attacks, attributed to the Russian state-sponsored hacking group Laundry Bear (also known as Void Blizzard), combine phishing campaigns with the exploitation of a patched flaw to compromise user accounts.
Laundry Bear has targeted a wide range of organizations, including those associated with the Defense Industrial Base (DIB), federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology. The attackers specifically focus on exploiting the Zimbra CVE-2025-66376 flaw, which allows JavaScript embedded in specially crafted HTML emails to execute automatically when a victim views the message.
This zero-day exploit enables attackers to steal account data without requiring users to click a link or visit a phishing site. According to the US Cybersecurity and Infrastructure Security Agency (CISA), Laundry Bear exploits this vulnerability as part of its attack chain, which also involves using adversary-in-the-middle (AiTM) phishing kits designed to impersonate legitimate Zimbra login portals.
The attackers use the stolen information to gain unauthorized access to email accounts, bypassing multi-factor authentication (MFA) in the process. They then create and send back a new Zimbra application passcode to legacy email clients like IMAP or ActiveSync, allowing them to retain access to the compromised account. The malware exfiltrates the stolen data over both DNS and HTTPS to an actor-controlled server running the group’s “Flowerbed” collection framework.
Laundry Bear’s tactics are particularly concerning given its focus on intelligence collection against organizations aligned with Russian strategic interests. Since at least 2024, the group has targeted NATO member states and Ukraine, compromising sensitive information from various sectors, including defense, transportation, and aviation.
The good news is that CISA has issued indicators of compromise (IOCs) to help affected organizations identify potential threats. To mitigate these attacks, security teams should prioritize updating Zimbra software to install all available security updates. They should also review the published IOCs, investigate systems for connections to identified domains and IP addresses, monitor for suspicious authentication activity, and revoke any unauthorized application passcodes.
In addition to implementing these fixes, organizations can take a proactive approach by investing in phishing-resistant multi-factor authentication where possible. This will significantly reduce the risk of successful attacks like those carried out by Laundry Bear.
Ultimately, the threat posed by Laundry Bear highlights the importance of prioritizing security updates and staying vigilant against emerging threats. As the attack surface continues to expand, it’s essential for organizations to test their defenses regularly and implement robust cybersecurity measures to stay ahead of sophisticated attackers. By taking proactive steps to secure their systems, organizations can minimize the risk of successful attacks and protect sensitive information from falling into the wrong hands.
Source: Bleeping Computer — 2026-07-23