Russian State-Backed Hackers Exploit Zimbra Zero-Day Vulnerability Against US and Ukraine Targets
A sophisticated Russian state-sponsored threat group, known as “Laundry Bear,” has been using a previously unknown vulnerability in the Zimbra Collaboration Suite (ZCS) to breach networks of Western governments and enterprises. The attack, which involves a “half-click” phishing campaign, has compromised networks across more than a dozen countries since at least July 2025.
The Laundry Bear group’s tactics are particularly insidious because they require only that a victim preview or open an email in their Zimbra webmail account. This means that even if the user doesn’t click on any links or download attachments, the attackers can still gain access to sensitive information. According to intelligence and cybersecurity agencies from 15 countries, Laundry Bear has been using this vulnerability, tracked as CVE-2025-66376, to gather sensitive information for the Russian Federation.
The Zimbra zero-day vulnerability was patched in November 2025 with the release of version 10.1.13, but the company’s initial release notes only mentioned it as a stored XSS vulnerability without providing any further details. It wasn’t until early January that the National Institute of Standards and Technology (NIST) and Mitre published entries for the flaw. Zimbra and its parent company Synacor failed to respond to Dark Reading’s request for comment on the delayed disclosure.
Laundry Bear’s “half-click” phishing campaign is a significant escalation in their tactics, which have previously relied on unsophisticated methods such as password spraying and conventional phishing attacks. According to Proofpoint researchers, who contributed to the government investigations into Laundry Bear, the Zimbra vulnerability allows attackers to craft emails that only need to be opened or previewed by a victim to run arbitrary JavaScript and collect sensitive information.
The attack is particularly concerning because it highlights the ongoing threat from Russian APTs against US organizations. The joint advisory issued by multiple countries warns that this campaign is “almost certainly” designed to gather sensitive information for the Russian Federation, and that Laundry Bear’s attacks mark yet another threat from Russian state-sponsored actors.
What does this mean for users of Zimbra? First and foremost, it’s essential to ensure that you’re running the latest version of ZCS, which should include the patch for CVE-2025-66376. Additionally, be cautious when receiving emails in your Zimbra webmail account – even if an email is from a trusted sender, it’s always better to err on the side of caution and report any suspicious activity to your IT department or cybersecurity team.
Source: Dark Reading — 2026-07-23