Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
Russian state-sponsored threat actors, dubbed ‘Laundry Bear,’ have been exploiting a zero-day vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite to target Western governments and enterprises, including US and Ukrainian entities, since July 2025. The group uses a ‘half-click’ phishing campaign requiring only email preview to steal 90 days of user messages and exfiltrate data to a command-and-control server. The vulnerability was initially identified by the Netherlands General Intelligence and Security Service (AIVD) in May, and the US CISA added it to its Known Exploited Vulnerabilities catalog in March, highlighting a significant and ongoing threat.
A joint advisory from the US government and multiple allied nations warns of a sustained and sophisticated attack campaign led by Russian state-backed threat actors, known as ‘Laundry Bear.’ Since July 2025, these actors have been leveraging a zero-day vulnerability (CVE-2025-66376) within Zimbra Collaboration Suite (ZCS) to compromise networks of Western governments and enterprises. The attack utilizes a ‘half-click’ phishing campaign – a novel approach where victims only need to open or preview a malicious email within a vulnerable Zimbra webmail server to trigger an exploit.
Unlike traditional phishing that requires users to click links or open attachments, Laundry Bear’s tactic allows the threat actors to steal 90 days’ worth of user messages and exfiltrate the data to a command-and-control (C2) server. Cybersecurity firm Seqrite first reported the exploitation activity in March, attributing it to the APT group ‘Fancy Bear’ (APT28). The National Institute of Standards and Technology (NIST) and Mitre followed suit, publishing their analyses in early January.
Intelligence agencies from 15 different countries have confirmed that the exploitation activity began at least five months prior to March, with Laundry Bear previously relying on less advanced methods like password spraying and conventional phishing. The Netherlands General Intelligence and Security Service (AIVD) initially identified Laundry Bear in May as a new Russian state-sponsored APT adjacent to other established groups.
Proofpoint researchers explain that the vulnerability was likely gifted to Laundry Bear by Russian intelligence agencies, and they warn that the APT group may be utilizing large language models (LLMs) to develop a bypass for Zimbra’s patch and continue targeting Zimbra servers. The joint advisory urges ZCS customers to immediately update their software to a fixed version or, if patching is not possible, switch to alternative webmail clients, and advises system administrators to closely monitor any Internet-connected ZCS instances or email systems for signs of compromise.
