Skip to content

Russian Hackers Exploit Zimbra Zero-Day Vulnerability for Email Theft

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a Russian state-sponsored hacking group exploiting a now-patched zero-click vulnerability in Zimbra email servers. The hackers, known as Laundry Bear or Void Blizzard, are targeting organizations using the Zimbra Collaboration Suite’s Classic UI, which is vulnerable to cross-site scripting (XSS) attacks.

According to CISA, Laundry Bear has targeted and compromised users in various sectors, including Defense Industrial Base (DIB), federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology. The attackers exploit the Zimbra CVE-2025-66376 flaw, which allows JavaScript embedded in specially crafted HTML emails to execute automatically when a victim views the message.

This zero-click vulnerability enables attackers to steal account data without requiring the user to click a link or visit a phishing site. CISA reports that Laundry Bear exploited the flaw as a zero-day before Zimbra patched it in November 2025 and continues to target organizations running unpatched servers. The vulnerability was later tagged by CISA as actively exploited in attacks.

The attackers use the exploit to automatically collect and send the victim’s last 90 days of emails, email address, password, Global Address List (GAL), and two-factor authentication (2FA) tokens. They also create and send back a new Zimbra application passcode, which is used by legacy email clients like IMAP or ActiveSync that do not support the TOTP authentication flows.

Laundry Bear’s malware exfiltrates stolen information over both DNS and HTTPS to an actor-controlled server running the group’s ‘Flowerbed’ collection framework. Smaller data is encoded and transmitted in DNS A-record queries, while larger payloads, including mailbox data, are uploaded over HTTPS as compressed archives to the attacker-controlled servers.

In addition to exploiting the Zimbra flaw, Laundry Bear also utilizes adversary-in-the-middle (AiTM) phishing kits designed to impersonate legitimate Zimbra login portals. These kits steal credentials and session cookies, allowing the attackers to gain access to targets’ email accounts.

CISA has released indicators of compromise (IOCs) that show the campaign used sites that impersonate Zimbra infrastructure, using domain names like ‘mailnalysis.com’, ’emailanalytics.com.ua’, ‘zimbrastat.com’, ‘zimbra-metadata.com’, ‘istc-cloud.com’, and ‘zmailanalytics.com’.

To mitigate this threat, CISA recommends that organizations using Zimbra:

* Update to the latest version of the software to install all available security updates.

* Review the published IOCs.

* Investigate systems for connections to the identified domains and IP addresses.

* Monitor for suspicious authentication activity.

* Revoke any unauthorized application passcodes, especially those with the ‘ZimbraWeb’.

* Review accounts for unauthorized mailbox access.

CISA also recommends implementing phishing-resistant multi-factor authentication where possible.

Laundry Bear has been attributed to cyberespionage attacks since May 2025 by Dutch intelligence agencies. The group has focused on intelligence collection against organizations aligned with Russian strategic interests, primarily targeting NATO member states and Ukraine.

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *