Russian group Laundry Bear exploits Zimbra bug to steal email data
This digest was compiled by AI from multiple sources — links to the originals are below.

A Russian state-sponsored hacking group known as Laundry Bear has been exploiting a zero-day vulnerability in Zimbra Collaboration Suite since July 2025 to steal sensitive data from governments and organizations in Western countries, U.S. and allied cyber officials warned Thursday. The exploit, which requires no user interaction, allows attackers to steal 90 days of email, passwords, and authentication tokens. The campaign targets sectors including defense, energy, and finance, with victims in Ukraine used as a testbed before broader deployment.
The Vulnerability
The exploit targets CVE-2025-66376, a zero-click vulnerability in Zimbra Collaboration Suite that was patched in November 2025, five months after attacks began. The flaw carries a medium severity rating of 6.1, highlighting the challenge of prioritizing patches based on severity alone. The exploit requires only a view of a phishing email and allows attackers to steal 90 days of email, account passwords, search history, email directories, two-factor authentication tokens, and newly created passwords.
Attribution and Tactics
Laundry Bear, also tracked as Void Blizzard, is a Russian state-sponsored group active since at least 2024. The group uses a custom JavaScript payload delivered via phishing emails and a novel data exfiltration capability dubbed 'beehive,' which officials say could be adapted to other vulnerabilities. 'The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group's involvement in espionage activities with Russian government backing,' the advisory states.
Targeting and Impact
The campaign has compromised governments and organizations in defense, education, energy, law enforcement, media, finance, transportation, and technology sectors. Officials noted extensive Ukrainian targeting prior to use against U.S. and NATO allies, describing Ukraine as a 'testbench' for malicious techniques. The group manually identifies victims with public-facing infrastructure and compiles email addresses for targeted phishing. Specific victims and the total number of compromised organizations were not disclosed.
What's Next
Authorities have released indicators of compromise and mitigation steps, urging organizations to patch vulnerable Zimbra instances. It remains unclear how many unpatched servers remain exposed or whether Laundry Bear will adapt the beehive capability to target other software.
2 sources
Russian group Laundry Bear exploits Zimbra bug to steal email data



