Russian hackers exploit Zimbra zero-click flaw for email theft
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]
AI Analysis
Technical Summary
Laundry Bear, a Russian state-sponsored hacking group, targeted organizations using Zimbra Collaboration Suite by exploiting CVE-2025-66376, a zero-click cross-site scripting vulnerability in the Classic UI. This vulnerability allowed embedded JavaScript in crafted HTML emails to execute automatically upon viewing, enabling attackers to steal account data including emails from the last 90 days, email addresses, passwords, Global Address List, and two-factor authentication tokens. The attackers also generated Zimbra application passcodes to maintain access via legacy clients, bypassing MFA protections. Data exfiltration occurred over DNS and HTTPS to attacker-controlled servers running the 'Flowerbed' framework. Additionally, Laundry Bear used adversary-in-the-middle phishing kits impersonating Zimbra login portals to harvest credentials and session cookies. The vulnerability was actively exploited before being patched in November 2025. CISA recommends updating Zimbra to the latest version, reviewing IOCs, investigating suspicious connections and authentication activity, revoking unauthorized application passcodes, and implementing phishing-resistant MFA.
Potential Impact
Successful exploitation allows attackers to steal extensive email data, credentials, and two-factor authentication tokens without requiring user interaction, enabling persistent unauthorized access to email accounts. The attackers can bypass multi-factor authentication by creating application passcodes for legacy clients. This compromises confidentiality and integrity of email communications and potentially broader organizational security. The vulnerability was actively exploited in the wild by a sophisticated state-sponsored group targeting government, defense, law enforcement, energy, media, education, and NGO sectors.
Mitigation Recommendations
Zimbra patched the vulnerability in November 2025. Organizations should update to the latest Zimbra version to apply all security updates. CISA recommends reviewing published indicators of compromise, investigating systems for connections to identified malicious domains and IPs, monitoring for suspicious authentication activity, revoking unauthorized application passcodes (especially those labeled 'ZimbraWeb'), and reviewing accounts for unauthorized mailbox access. Implement phishing-resistant multi-factor authentication where possible. These steps address both the vulnerability exploitation and associated phishing campaigns.
Russian hackers exploit Zimbra zero-click flaw for email theft
Description
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Laundry Bear, a Russian state-sponsored hacking group, targeted organizations using Zimbra Collaboration Suite by exploiting CVE-2025-66376, a zero-click cross-site scripting vulnerability in the Classic UI. This vulnerability allowed embedded JavaScript in crafted HTML emails to execute automatically upon viewing, enabling attackers to steal account data including emails from the last 90 days, email addresses, passwords, Global Address List, and two-factor authentication tokens. The attackers also generated Zimbra application passcodes to maintain access via legacy clients, bypassing MFA protections. Data exfiltration occurred over DNS and HTTPS to attacker-controlled servers running the 'Flowerbed' framework. Additionally, Laundry Bear used adversary-in-the-middle phishing kits impersonating Zimbra login portals to harvest credentials and session cookies. The vulnerability was actively exploited before being patched in November 2025. CISA recommends updating Zimbra to the latest version, reviewing IOCs, investigating suspicious connections and authentication activity, revoking unauthorized application passcodes, and implementing phishing-resistant MFA.
Potential Impact
Successful exploitation allows attackers to steal extensive email data, credentials, and two-factor authentication tokens without requiring user interaction, enabling persistent unauthorized access to email accounts. The attackers can bypass multi-factor authentication by creating application passcodes for legacy clients. This compromises confidentiality and integrity of email communications and potentially broader organizational security. The vulnerability was actively exploited in the wild by a sophisticated state-sponsored group targeting government, defense, law enforcement, energy, media, education, and NGO sectors.
Mitigation Recommendations
Zimbra patched the vulnerability in November 2025. Organizations should update to the latest Zimbra version to apply all security updates. CISA recommends reviewing published indicators of compromise, investigating systems for connections to identified malicious domains and IPs, monitoring for suspicious authentication activity, revoking unauthorized application passcodes (especially those labeled 'ZimbraWeb'), and reviewing accounts for unauthorized mailbox access. Implement phishing-resistant multi-factor authentication where possible. These steps address both the vulnerability exploitation and associated phishing campaigns.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/","fetched":true,"fetchedAt":"2026-07-23T16:52:13.252Z","wordCount":905}
- Classification
- {"confidence":0.74,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a6246be9c2644c7f8641461
Added to database: 07/23/2026, 16:52:14 UTC
Last enriched: 07/23/2026, 16:52:37 UTC
Last updated: 09/05/2026, 15:27:54 UTC
Views: 151
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.