Russian state-linked hackers have used a patched Zimbra zero-click flaw to steal emails, account credentials and multi-factor authentication tokens from targeted organisations.
The US Cybersecurity and Infrastructure Security Agency (CISA) says the group, known as Laundry Bear or Void Blizzard, combines the Zimbra vulnerability with phishing attacks that impersonate legitimate email login portals.
Zero-click Zimbra flaw steals mailbox data
The attackers exploit CVE-2025-66376, a cross-site scripting vulnerability in the Classic UI of Zimbra Collaboration Suite.
A specially crafted HTML email can run embedded JavaScript automatically when the recipient views the message. As a result, attackers can collect account data without requiring the victim to click a link or visit a phishing website.
Laundry Bear reportedly exploited the Zimbra zero-click flaw before Zimbra released a patch in November 2025. The group continues to target organisations that have not installed the available update.
CISA has also listed the vulnerability as actively exploited.
Attackers collect emails and MFA tokens
CISA says the malicious code can collect the victim’s most recent 90 days of emails, email address, password, Global Address List entries and two-factor authentication tokens.
The attackers also create a new Zimbra application passcode and send it back to their infrastructure. These passcodes support older email clients, such as IMAP and ActiveSync, that do not use time-based one-time password authentication.
By creating an application passcode, the group can retain access to the account while bypassing multi-factor authentication protections.
The campaign sends smaller stolen data through DNS A-record queries. It sends larger data, including mailbox archives, over HTTPS to attacker-controlled servers running the group’s Flowerbed collection framework.
Phishing sites imitate Zimbra login portals
Alongside the exploit, Laundry Bear uses adversary-in-the-middle phishing kits that copy legitimate Zimbra login pages. These sites aim to capture user credentials and session cookies.
CISA identified several domains used to imitate Zimbra-related infrastructure, including mailnalysis.com, emailanalytics.com.ua, zimbrastat.com, zimbra-metadata.com, istc-cloud.com and zmailanalytics.com.
The agency advises Zimbra administrators to install the latest software updates, review published indicators of compromise and investigate connections to the identified domains and IP addresses.
Organisations should also monitor for unusual authentication activity, review accounts for unauthorised mailbox access and revoke suspicious application passcodes, particularly those labelled “ZimbraWeb.” CISA further recommends phishing-resistant multi-factor authentication where it is available.
Laundry Bear targets NATO countries and Ukraine
Dutch intelligence agencies publicly attributed Laundry Bear to Russian cyberespionage activity in May 2025. The group was linked to a 2024 compromise of the Dutch National Police that exposed personal information belonging to police personnel.
Microsoft tracks the same threat actor as Void Blizzard. Since at least 2024, the group has focused on intelligence gathering against organisations that align with Russian strategic interests, particularly in NATO member states and Ukraine.
Its targets have included organisations in the defence industrial base, government, education, energy, law enforcement, media, technology and non-governmental sectors.


0 responses to “Zimbra Zero-Click Flaw Used in Russian Email Theft Attacks”