Russian hackers exploit Zimbra zero-click flaw for email theft
The Russian state-sponsored group Laundry Bear (Void Blizzard) exploited a now-patched zero-click cross-site scripting (XSS) vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite's Classic UI to steal email data. The flaw allowed malicious JavaScript in specially crafted emails to execute automatically when viewed, enabling attackers to exfiltrate emails, credentials, and two-factor authentication tokens without user interaction. The group combined this exploit with phishing campaigns using adversary-in-the-middle kits to steal credentials and session cookies. The attackers also created application passcodes to bypass multi-factor authentication for legacy email clients. CISA has issued warnings and indicators of compromise to help organizations detect and respond to these attacks. The vulnerability was patched by Zimbra in November 2025.
AI Analysis
Technical Summary
Laundry Bear, a Russian state-sponsored hacking group, targeted organizations using Zimbra Collaboration Suite by exploiting CVE-2025-66376, a zero-click cross-site scripting vulnerability in the Classic UI. This vulnerability allowed embedded JavaScript in crafted HTML emails to execute automatically upon viewing, enabling attackers to steal account data including emails from the last 90 days, email addresses, passwords, Global Address List, and two-factor authentication tokens. The attackers also generated Zimbra application passcodes to maintain access via legacy clients, bypassing MFA protections. Data exfiltration occurred over DNS and HTTPS to attacker-controlled servers running the 'Flowerbed' framework. Additionally, Laundry Bear used adversary-in-the-middle phishing kits impersonating Zimbra login portals to harvest credentials and session cookies. The vulnerability was actively exploited before being patched in November 2025. CISA recommends updating Zimbra to the latest version, reviewing IOCs, investigating suspicious connections and authentication activity, revoking unauthorized application passcodes, and implementing phishing-resistant MFA.
Potential Impact
Successful exploitation allows attackers to steal extensive email data, credentials, and two-factor authentication tokens without requiring user interaction, enabling persistent unauthorized access to email accounts. The attackers can bypass multi-factor authentication by creating application passcodes for legacy clients. This compromises confidentiality and integrity of email communications and potentially broader organizational security. The vulnerability was actively exploited in the wild by a sophisticated state-sponsored group targeting government, defense, law enforcement, energy, media, education, and NGO sectors.
Mitigation Recommendations
Zimbra patched the vulnerability in November 2025. Organizations should update to the latest Zimbra version to apply all security updates. CISA recommends reviewing published indicators of compromise, investigating systems for connections to identified malicious domains and IPs, monitoring for suspicious authentication activity, revoking unauthorized application passcodes (especially those labeled 'ZimbraWeb'), and reviewing accounts for unauthorized mailbox access. Implement phishing-resistant multi-factor authentication where possible. These steps address both the vulnerability exploitation and associated phishing campaigns.
Russian hackers exploit Zimbra zero-click flaw for email theft
Description
The Russian state-sponsored group Laundry Bear (Void Blizzard) exploited a now-patched zero-click cross-site scripting (XSS) vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite's Classic UI to steal email data. The flaw allowed malicious JavaScript in specially crafted emails to execute automatically when viewed, enabling attackers to exfiltrate emails, credentials, and two-factor authentication tokens without user interaction. The group combined this exploit with phishing campaigns using adversary-in-the-middle kits to steal credentials and session cookies. The attackers also created application passcodes to bypass multi-factor authentication for legacy email clients. CISA has issued warnings and indicators of compromise to help organizations detect and respond to these attacks. The vulnerability was patched by Zimbra in November 2025.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Laundry Bear, a Russian state-sponsored hacking group, targeted organizations using Zimbra Collaboration Suite by exploiting CVE-2025-66376, a zero-click cross-site scripting vulnerability in the Classic UI. This vulnerability allowed embedded JavaScript in crafted HTML emails to execute automatically upon viewing, enabling attackers to steal account data including emails from the last 90 days, email addresses, passwords, Global Address List, and two-factor authentication tokens. The attackers also generated Zimbra application passcodes to maintain access via legacy clients, bypassing MFA protections. Data exfiltration occurred over DNS and HTTPS to attacker-controlled servers running the 'Flowerbed' framework. Additionally, Laundry Bear used adversary-in-the-middle phishing kits impersonating Zimbra login portals to harvest credentials and session cookies. The vulnerability was actively exploited before being patched in November 2025. CISA recommends updating Zimbra to the latest version, reviewing IOCs, investigating suspicious connections and authentication activity, revoking unauthorized application passcodes, and implementing phishing-resistant MFA.
Potential Impact
Successful exploitation allows attackers to steal extensive email data, credentials, and two-factor authentication tokens without requiring user interaction, enabling persistent unauthorized access to email accounts. The attackers can bypass multi-factor authentication by creating application passcodes for legacy clients. This compromises confidentiality and integrity of email communications and potentially broader organizational security. The vulnerability was actively exploited in the wild by a sophisticated state-sponsored group targeting government, defense, law enforcement, energy, media, education, and NGO sectors.
Mitigation Recommendations
Zimbra patched the vulnerability in November 2025. Organizations should update to the latest Zimbra version to apply all security updates. CISA recommends reviewing published indicators of compromise, investigating systems for connections to identified malicious domains and IPs, monitoring for suspicious authentication activity, revoking unauthorized application passcodes (especially those labeled 'ZimbraWeb'), and reviewing accounts for unauthorized mailbox access. Implement phishing-resistant multi-factor authentication where possible. These steps address both the vulnerability exploitation and associated phishing campaigns.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/","fetched":true,"fetchedAt":"2026-07-23T16:52:13.252Z","wordCount":905}
Threat ID: 6a6246be9c2644c7f8641461
Added to database: 07/23/2026, 16:52:14 UTC
Last enriched: 07/23/2026, 16:52:37 UTC
Last updated: 07/24/2026, 03:48:29 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.