● Vulnerabilities

Russian Hackers Exploit Zimbra Zero-Click Flaw for Email Theft

July 23, 2026 · snewle
Russian Hackers Exploit Zimbra Zero-Click Flaw for Email Theft

A Russian state-sponsored hacking group known as Laundry Bear, also tracked as Void Blizzard, is actively exploiting a patched Zimbra Collaboration vulnerability to steal emails and credentials from government, defense, and critical infrastructure organizations. The Cybersecurity and Infrastructure Security Agency has issued an advisory warning that the group combines phishing attacks with exploitation of the Zimbra zero-click flaw to compromise sensitive accounts.

According to CISA, Laundry Bear has successfully targeted organizations across multiple sectors including the Defense Industrial Base, federal and local government agencies, education institutions, energy companies, law enforcement, media outlets, non-governmental organizations, and technology firms. The threat actor exploited the vulnerability as a zero-day before it was patched in November 2025.

How Does the Zimbra Zero-Click Attack Work?

The attackers exploit CVE-2025-66376, a cross-site scripting vulnerability affecting Zimbra Collaboration Suite’s Classic UI. The flaw enables JavaScript embedded in specially crafted HTML emails to execute automatically when a victim simply views the message. This zero-click exploit requires no user interaction such as clicking links or visiting phishing sites.

CISA reports that Laundry Bear’s exploit automatically collects and exfiltrates the victim’s last 90 days of emails, email addresses, passwords, Global Address List data, and two-factor authentication tokens. The malware also generates and sends back a new Zimbra application passcode, which legacy email clients like IMAP or ActiveSync use when they don’t support TOTP authentication flows. This passcode mechanism allows attackers to maintain persistent access to email accounts while bypassing multi-factor authentication protections.

What Data Exfiltration Methods Are Used?

Stolen information is exfiltrated through multiple channels to an actor-controlled server running the group’s ‘Flowerbed’ collection framework. Smaller data sets are encoded and transmitted in DNS A-record queries, while larger payloads including complete mailbox data are uploaded over HTTPS as compressed archives to attacker-controlled infrastructure.

Beyond exploiting the Zimbra vulnerability, Laundry Bear also deploys adversary-in-the-middle phishing kits that impersonate legitimate Zimbra login portals. These phishing operations steal credentials and session cookies, providing alternative access paths to targeted email accounts. CISA released indicators of compromise showing the campaign used domains impersonating Zimbra infrastructure, including ‘mailnalysis.com’, ’emailanalytics.com.ua’, ‘zimbrastat.com’, ‘zimbra-metadata.com’, ‘istc-cloud.com’, and ‘zmailanalytics.com’.

What Should Organizations Do to Protect Themselves?

CISA recommends that organizations using Zimbra immediately update to the latest software version to install all available security patches. Administrators should review published indicators of compromise and investigate systems for connections to identified malicious domains and IP addresses. Organizations should monitor for suspicious authentication activity, revoke any unauthorized application passcodes (especially those containing ‘ZimbraWeb’), and review accounts for unauthorized mailbox access. CISA also recommends implementing phishing-resistant multi-factor authentication wherever possible.

The Laundry Bear group was first publicly attributed to cyberespionage activities in May 2025 by Dutch intelligence agencies following a 2024 compromise of the Dutch National Police. Since at least 2024, the group has focused on intelligence collection against organizations aligned with Russian strategic interests, primarily targeting NATO member states and Ukraine.

Source: BleepingComputer