Russian hackers exploit Zimbra zero-click flaw for email theft

Russian Hackers Exploit Zimbra Vulnerability to Steal Email Data from Organizations Worldwide

A sophisticated hacking group backed by the Russian government has been using a previously patched vulnerability in Zimbra email servers to steal sensitive data, including emails, passwords, and two-factor authentication (2FA) tokens. The attackers, known as Laundry Bear or Void Blizzard, have targeted organizations in various sectors, including defense, education, energy, law enforcement, media, non-governmental organizations, and technology.

The vulnerability, CVE-2025-66376, is a cross-site scripting (XSS) flaw affecting Zimbra Collaboration Suite’s Classic UI. It allows attackers to execute malicious JavaScript code automatically when a victim views a specially crafted email, enabling them to steal account data without requiring the user to click on a link or visit a phishing site. The attackers have been exploiting this zero-day vulnerability before it was patched in November 2025 and continue to target organizations running unpatched servers.

Laundry Bear’s exploitation of the Zimbra flaw is particularly concerning, as it allows them to automatically collect and send sensitive data from victims’ email accounts. According to the US Cybersecurity and Infrastructure Security Agency (CISA), the attackers use a combination of phishing attacks and the exploited vulnerability to steal account information, including emails, passwords, Global Address List (GAL) entries, and 2FA tokens. The attackers also create and send new Zimbra application passcodes, which are used by legacy email clients that do not support Time-Based One-Time Password (TOTP) authentication flows.

The stolen data is exfiltrated over both DNS and HTTPS to an actor-controlled server running the group’s “Flowerbed” collection framework. Smaller payloads are encoded and transmitted in DNS A-record queries, while larger files are uploaded over HTTPS as compressed archives to the attacker-controlled servers.

In addition to exploiting the Zimbra vulnerability, Laundry Bear also uses adversary-in-the-middle (AiTM) phishing kits designed to impersonate legitimate Zimbra login portals, stealing credentials and session cookies. This allows the attackers to gain access to targets’ email accounts without needing to exploit the vulnerability.

The CISA has released indicators of compromise (IOCs) that show the campaign used sites that impersonate Zimbra infrastructure, including domain names like ‘mailnalysis.com’, ’emailanalytics.com.ua’, and ‘zimbrastat.com’. The agency recommends that organizations using Zimbra update to the latest version of the software to install all available security updates. They also advise reviewing the published IOCs, investigating systems for connections to identified domains and IP addresses, monitoring for suspicious authentication activity, revoking unauthorized application passcodes, and reviewing accounts for unauthorized mailbox access.

Laundry Bear has a history of targeting governments, police, and Ukraine-aligned organizations, with Microsoft documenting successful compromises of entities in the defense, transportation, and aviation sectors. This latest campaign highlights the importance of staying vigilant and regularly updating software to prevent attacks like this from succeeding.

As we’ve seen time and time again, security teams often fail to detect attacks until it’s too late. According to recent research, 54% of successful attacks are logged by security teams after they’ve already occurred, with only 14% detected in real-time. Regular breach and attack simulation tests can help identify vulnerabilities and ensure that SIEM and EDR rules are effective in detecting threats. By testing every layer of our defenses before attackers do, we can prevent such attacks from succeeding in the first place.


Source: Bleeping Computer — 2026-07-23