Russian state-supported hackers have launched a sophisticated espionage campaign using a zero-click attack technique that compromises organizations without requiring any user interaction with malicious emails. The campaign, targeting Western government and commercial entities, has been active since at least July 2025 according to a joint advisory issued on July 23 by international intelligence agencies.
Which Organizations Are Being Targeted?
The espionage operation has focused on organizations across multiple critical sectors including defense, government, education, energy, law enforcement, media, NGO and technology. The threat actors, identified as Laundry Bear (also known as Void Blizzard and UAC-0190), specifically exploit organizations using Zimbra Collaboration Suite (ZCS) software to gain persistent network access and steal sensitive information.
The joint advisory was issued by the UK National Cyber Security Centre, US agencies including CISA, NSA and the FBI, along with cyber and intelligence agencies from the Five Eyes nations (Canada, Australia and New Zealand) and European agencies.
How Does the Zero-Click Exploit Work?
The campaign exploits a zero-day vulnerability in ZCS identified as CVE-2025-66376, which was publicly disclosed in November 2025. Unlike traditional phishing campaigns that require users to click links or open files, this attack leverages a view-based exploit dubbed “beehive” that activates simply when a user views a malicious email within a vulnerable version of the webmail service.
Once successful, the attackers exfiltrate at least the last 90 days of emails from compromised servers along with other sensitive data. The threat actors also work to maintain persistence on victim networks by secretly stealing passwords and circumventing multi-factor authentication protections through session tokens.
What Action Should Organizations Take?
Organizations using ZCS have been urged to immediately patch the critical vulnerability and enhance network monitoring capabilities. Beth Hopkins, COO of the NCSC, stated that “this phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations.”
The advisory recommends system administrators watch for suspicious activity and consider implementing third-party authentication services that support passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. This approach can help eliminate the possibility of threat actors exploiting stolen credentials to access servers.
AI Used in Attack Development
Technical analysis of the campaign indicated that AI played a role in developing a simple codebase for the operation, highlighting concerns intelligence agencies have previously raised about malicious threat actors harnessing AI in their campaigns.
Source: Infosecurity Magazine