Russian hackers exploit Zimbra zero-click flaw for email theft
Russian hackers, part of the Laundry Bear group, are exploiting a zero-click flaw in Zimbra email servers to steal user data. The flaw, patched in November 2025, allows attackers to steal emails, passwords, and 2FA tokens without requiring user interaction.
Intelligence analysis by Llama

Russian hackers are exploiting a zero-click flaw in Zimbra email servers to steal user data. The flaw, patched in November 2025, allows attackers to steal emails, passwords, and 2FA tokens without requiring user interaction. The attackers are using phishing attacks and adversary-in-the-middle (AiTM) kits to gain access to targets' email accounts.
Imagine you receive an email that looks like it's from your email provider, but it's actually from a hacker. The hacker can steal your email, password, and special security codes without you even clicking on anything. This is called a zero-click flaw, and it's a big problem because it lets hackers get into your email account without you even knowing it.
Analysis
A Zero-Click Flaw in Zimbra Email Servers
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, has been exploiting a zero-click flaw in Zimbra email servers to steal user data. The flaw, patched in November 2025, allows attackers to steal emails, passwords, and 2FA tokens without requiring user interaction. This exploit is particularly concerning because it demonstrates the ability of attackers to bypass traditional security measures and gain access to sensitive information.
The Exploit of the Zero-Click Flaw
The attackers are using phishing attacks and adversary-in-the-middle (AiTM) kits to gain access to targets' email accounts. The phishing attacks are designed to impersonate legitimate Zimbra login portals, stealing credentials and session cookies. The AiTM kits are used to create and send back a new Zimbra application passcode, which is used by legacy email clients like IMAP or ActiveSync that do not support the TOTP authentication flows.
The Importance of Keeping Software Up-to-Date
The exploit of the zero-click flaw highlights the importance of keeping software up-to-date. Organizations using Zimbra email servers must ensure that they have installed all available security updates to prevent such attacks. Additionally, implementing robust security measures, such as phishing-resistant multi-factor authentication, can help prevent attackers from gaining access to sensitive information.
Key points
- Russian hackers are exploiting a zero-click flaw in Zimbra email servers to steal user data.
- The flaw, patched in November 2025, allows attackers to steal emails, passwords, and 2FA tokens without requiring user interaction.
- The attackers are using phishing attacks and adversary-in-the-middle (AiTM) kits to gain access to targets' email accounts.
- Organizations using Zimbra email servers must ensure that they have installed all available security updates to prevent such attacks.
- Implementing robust security measures, such as phishing-resistant multi-factor authentication, can help prevent attackers from gaining access to sensitive information.
If organizations using Zimbra email servers update to the latest version of the software and implement robust security measures, they can prevent such attacks from occurring. Additionally, the release of IOCs by CISA can help organizations identify and mitigate the threat.
The exploit of the zero-click flaw demonstrates the ongoing threat of Russian state-sponsored hacking groups targeting organizations using Zimbra email servers. The attackers may continue to exploit this flaw until it is fully patched, and organizations must remain vigilant to prevent such attacks.



