Russian Espionage Campaign Targets Zimbra Webmail with Zero-Click Exploits
A Russian cyberespionage campaign, tracked as CL-STA-1114 and attributed to the Void Blizzard/LAUNDRY BEAR threat actor, is actively exploiting a zero-day vulnerability in Zimbra Collaboration Suite (ZCS) to steal sensitive user credentials and data.

A sophisticated cyberespionage campaign, identified by Unit 42 as CL-STA-1114 and linked to Russian threat actors known as Void Blizzard and LAUNDRY BEAR, has been actively targeting organizations globally. The campaign specifically focuses on exploiting vulnerabilities within the Zimbra Collaboration Suite (ZCS) webmail platform to facilitate espionage activities. This operation has been ongoing since at least 2024, with the targeted exploitation of Zimbra beginning in July 2025.
The primary targets of this campaign include government entities, defense contractors, transportation companies, and financial organizations. Geographically, the attackers are focusing on NATO member states, Ukraine, Commonwealth of Independent States (CIS) countries, and nations across Africa. The objective is to gain access to sensitive information stored within compromised email accounts, including credentials, historical communications, and search data.
A unique and concerning aspect of this campaign is its reliance on zero-click phishing emails. These emails exploit a vulnerability in ZCS, identified as CVE-2025-66376, which allows for the automatic injection of a malicious JavaScript payload without any user interaction. This means that simply receiving and opening an email with the malicious HTML content can lead to compromise, significantly lowering the barrier for attackers.
Upon execution, the injected JavaScript payload exfiltrates a wide range of sensitive user data to hard-coded command and control (C2) servers. This data includes critical items such as Cross-Site Request Forgery (CSRF) tokens, email addresses and passwords, two-factor authentication (2FA) scratch codes, system and environment details, and the victim's email and search history from the past 90 days. The payload has shown minimal changes throughout the observed campaign, indicating a stable and effective exploit.
The attack chain begins with a phishing email containing either an HTML attachment or embedded HTML within the message body. These lures are often designed to appear as legitimate news headlines to capture the recipient's attention. The HTML code contains an obfuscated section, typically Base64-encoded, which, when processed by the browser, decodes and injects the JavaScript payload. This payload then silently communicates with the attacker's C2 infrastructure.
Unit 42 has identified at least nine distinct IP addresses and nine domains used as C2 servers throughout the campaign, with an average operational lifespan of approximately 35.4 days per server. The continuous use of these servers highlights the persistent nature of the threat actors and their efforts to maintain their infrastructure.
Palo Alto Networks emphasizes the critical need for organizations to remain vigilant, prioritize patching vulnerable ZCS instances, and implement advanced threat detection measures. Products like Cortex Advanced Email Security and Advanced URL Filtering can help mitigate these threats by analyzing suspicious attachments and blocking malicious domains. The Cyber Threat Alliance is also sharing this intelligence to enable rapid deployment of protections across member organizations.
This campaign underscores the evolving tactics of state-sponsored cyberespionage groups, who are increasingly targeting widely-used platforms like Zimbra to maximize their impact. The reliance on zero-click exploits and the exfiltration of extensive user data present a significant risk to critical industries worldwide, necessitating robust security postures and proactive defense strategies.
This NCSC advisory expands on the previously reported campaign by LAUNDRY BEAR, detailing the specific 'beehive' (or 'Ulej') exploit technique. It clarifies that the zero-click vulnerability affects Zimbra Collaboration Suite (ZCS) webmail and requires no user interaction beyond viewing a malicious email. The advisory also highlights that the threat actors extensively trialled these methods on Ukrainian victims before targeting NATO members, and notes the potential role of AI in developing the exploit's codebase.
This CISA alert provides further details on the ongoing campaign by LAUNDRY BEAR (also tracked as CL-STA-1114 and Void Blizzard) targeting Zimbra Collaboration Suite (ZCS). It highlights the use of a novel zero-day exploit, CVE-2025-66376, which allows for email exfiltration and persistent access simply by viewing a malicious email. The advisory also lists a broad coalition of international agencies endorsing its findings and recommendations.
This new reporting details that the Russian state-sponsored threat actor Void Blizzard, also known as Laundry Bear, has been actively exploiting CVE-2025-66376, a cross-site scripting vulnerability in Zimbra Collaboration Suite, since July 2025. The campaign, which predates the November 2025 patch for the vulnerability, allows for data exfiltration including emails, credentials, and 2FA tokens simply by victims viewing a malicious email. The attackers are reportedly using a custom framework called Flowerbed, which may have incorporated AI in its development, and are targeting a wide array of sectors including defense, government, and energy.
This new report details the exploitation of a zero-day vulnerability in Zimbra Collaboration Suite (ZCS), identified as CVE-2025-66376, by Russian state-sponsored hackers. The campaign, dubbed Laundry Bear, uses a "beehive" zero-click exploit that requires only viewing a malicious email to compromise systems, aiming to exfiltrate emails and sensitive data, and maintain persistence through stolen credentials and session tokens. The advisory highlights the role of AI in developing the operation's codebase and urges immediate patching and enhanced network monitoring.
This updated reporting confirms that the Russian state-sponsored group Laundry Bear (also known as Void Blizzard) has been actively exploiting a zero-day vulnerability, CVE-2025-66376, in Zimbra Collaboration Suite since at least July 2025. The exploit, which requires no user interaction, allows for the exfiltration of emails, credentials, and authentication tokens. The advisory, issued by a coalition of over a dozen Western countries, highlights the group's espionage objectives and a concerning trend of targeting Ukrainian entities first as a testing ground before broader attacks.
The new reporting details that the Russian-linked Laundry Bear group has been extensively targeting Ukrainian entities before shifting focus to U.S. and NATO organizations, suggesting Ukraine serves as a testing ground for their cyber techniques. Furthermore, the campaign is characterized by its covert and persistent nature, with no known financial extortion, strongly indicating espionage activities backed by the Russian government. The exploit involves a malicious JavaScript payload hidden in emails sent from compromised accounts, executed immediately upon opening, and aims to exfiltrate emails, passwords, and authentication tokens.
The Russian state-sponsored group, identified as Laundry Bear and also known as Void Blizzard, is actively exploiting the Zimbra CVE-2025-66376 vulnerability. This cross-site scripting flaw allows for the automatic execution of JavaScript in specially crafted HTML emails, enabling attackers to steal account data without user interaction. CISA has warned that the exploit can exfiltrate up to 90 days of emails, account credentials, and two-factor authentication tokens, and that the group continues to target unpatched Zimbra servers even after a November 2025 patch was released.
This new reporting details the specific technical mechanism of the exploit, dubbed ZimReaper, which uses a stored cross-site scripting vulnerability (CVE-2025-66376) in Zimbra's Classic UI. The attack leverages CSS @import handling and tag-splitting techniques within crafted HTML emails to execute JavaScript, stealing credentials, 2FA codes, and email data, and even minting app-specific passwords for persistent access.
This new reporting from Dark Reading provides further details on the "Laundry Bear" (also known as TA488) campaign, attributing the exploitation of the Zimbra zero-day (CVE-2025-66376) to Russian state-sponsored actors. The article highlights the sophisticated "half-click" phishing technique, which requires only viewing a malicious email to execute arbitrary JavaScript, exfiltrate data, and compromise Zimbra webmail servers. It also notes that while the campaign may have ceased in February following detection, other unclustered activity exploiting the flaw in unpatched servers has been observed.
This new reporting provides significant technical depth on the LAUNDRY BEAR campaign targeting Zimbra Collaboration Suite. It details the 'Ulej' framework's use of a zero-day (CVE-2025-66376) within SVG images to trigger code execution simply by viewing an email, bypassing the need for user interaction. Furthermore, the article elaborates on the 'Flowerbed' system's capabilities for exfiltrating up to 90 days of emails via HTTPS and DNS, and its potential use of AI tools in development.
This new reporting confirms that the specific vulnerability exploited by Laundry Bear is CVE-2025-66376, a cross-site scripting (XSS) flaw within the Zimbra Collaboration Suite. While the vulnerability was patched in November 2025, the threat actor has continued to leverage it against unpatched servers, demonstrating a persistent exploitation of known weaknesses. The attack vector involves embedding JavaScript in specially crafted HTML emails, which execute when viewed, allowing for the theft of account data, email contents, and authentication tokens without user interaction.
This new report details how Russian espionage actors, tracked as Laundry Bear, Void Blizzard, and TA488, are exploiting CVE-2025-66376, a cross-site scripting vulnerability in Zimbra Collaboration Suite. The attack, which has been ongoing since at least July 2025, allows for data theft, including emails and credentials, through a "half-click" exploit triggered simply by opening a malicious email in a vulnerable webmail client. The vulnerability was patched by Zimbra in November 2025, and a joint alert from over a dozen Western cybersecurity agencies highlights the continued threat and urges administrators to apply patches.
The Russian-aligned espionage group TA488, also known as Void Blizzard and Laundry Bear, has resumed operations with a novel attack targeting on-premises Outlook Web Access (OWA) environments. This new campaign, initiated on July 22, employs a sophisticated half-click exploit dubbed OWAReaper, which deploys a persistent, browser-resident implant capable of surviving system re-imaging and credential rotation. The group had been inactive since February, and this campaign has seen an unusual volume of activity targeting US and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors.
Researchers have revealed that the Russian state-linked hacking group Laundry Bear, also known as Void Blizzard, has escalated its activities beyond the previously reported Zimbra exploitation. The group began exploiting a vulnerability in Microsoft Outlook Web Access (OWA) just one day before the international alert regarding Zimbra was issued. This new campaign targets a broader range of sectors, including government, telecommunications, finance, hospitality, and aerospace, with the objective of stealing emails and credentials. The exploit chain utilizes a novel JavaScript browser-based implant named OWAReaper, which Proofpoint describes as the most sophisticated backdoor delivered via half-click exploits observed to date, featuring subtle persistence mechanisms. This indicates an advancement in the group's tradecraft and capabilities, with evidence suggesting they may have exploited the OWA vulnerability as a zero-day.
This new report details a sophisticated evolution of the Void Blizzard (Laundry Bear) campaign previously targeting Zimbra, now leveraging a zero-day cross-site scripting vulnerability (CVE-2026-42897) in Microsoft Exchange's Outlook Web Access (OWA). The exploit enables a 'half-click' attack where merely opening a crafted email allows the deployment of a new, advanced backdoor named OWAReaper, which employs subtle persistence mechanisms to maintain long-term mailbox access even after credential rotation or system restoration.