Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
CISA and a coalition of Western intelligence agencies warn that Russian APT group LAUNDRY BEAR has exploited a zero-day in Zimbra Collaboration Suite to harvest 90 days of email from victims since at least July 2025.
Intelligence analysis by Llama
A multi-nation cybersecurity advisory details how Russian state hackers used a view-based zero-day exploit in Zimbra to silently steal email and address books from Western government and commercial targets, with the flaw patched only after extensive exploitation.
Hackers from Russia found a secret trick that let them read people's emails just by sending them a message — the victim didn't even have to click anything. Lots of countries teamed up to warn everyone to update their Zimbra email software fast so the trick stops working.
Analysis
A View-Based Trap That Needs No Click
The campaign detailed in advisory AA26-204A marks a meaningful escalation in tradecraft for LAUNDRY BEAR, a Russian state-aligned APT tracked by allied intelligence services. Earlier operations relied on relatively blunt instruments — password spraying, phishing lures, and pass-the-cookie attacks — that depended on persuading a target to do something. The new approach, by contrast, exploits a vulnerability in the Zimbra Collaboration Suite webmail client where merely rendering a malicious message in the preview pane is enough to trigger compromise. According to the advisory, the exploit then attempts to siphon off the victim's previous 90 days of email, the organization's Global Address List, and other sensitive metadata to attacker-controlled servers, while also establishing persistence through a mix of credential and token techniques. The flaw, tracked as CVE-2025-66376, was a true zero-day at the moment of first exploitation and was not patched until November 2025 — meaning victims had months of exposure before a fix existed.
A Coalition Response of Unusual Breadth
What sets this advisory apart operationally is the sheer weight of the co-sealing coalition. CISA, the NSA, the FBI, the U.S. Department of the Treasury, the Naval Criminal Investigative Service, and the Defense Counterintelligence and Security Agency are joined by intelligence and cyber agencies from the Netherlands, Australia, Canada, New Zealand, the United Kingdom, the Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, Poland, Spain, and Sweden. That roster is not vanity — it reflects the geographic spread of confirmed victims and signals allied consensus on attribution. The Netherlands' AIVD and MIVD originally named the cluster LAUNDRY BEAR, and the advisory treats their assessment of Russian state backing as the consensus view across the entire partner network. For security teams, that translates into high-confidence indicators of compromise, hunting guidance, and remediation steps backed by threat intelligence from sixteen-plus governments.
Patch Now, But Expect The Next One
The authoring agencies are blunt about the road ahead. They expect LAUNDRY BEAR to abandon the current CVE-2025-66376 campaign as more organizations update, but assess it as "very likely" that the group will pivot to other Zimbra weaknesses or adjacent email platforms used by Western organizations. The advisory specifically warns that the actors "will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities" — a reminder that zero-day stockpiling for messaging platforms remains a Russian intelligence priority. For defenders, the practical implications are clear: any Zimbra deployment not yet on the November 2025 patch should be treated as actively at risk, email logs should be reviewed for the published IOCs, and the long tail of webmail and groupware platforms — often running as legacy infrastructure outside the modern EDR perimeter — deserves the same patching discipline as endpoint and cloud workloads.
Key points
- Russian APT group LAUNDRY BEAR exploited a Zimbra Collaboration Suite zero-day (CVE-2025-66376) since at least July 2025 to harvest 90 days of email and Global Address Lists from Western targets.
- The exploit required only that a victim view a malicious email in the webmail client — no clicks or file opens needed — a notable escalation from the group's earlier password-spraying and phishing techniques.
- The vulnerability was not patched until November 2025, leaving months of exposure before defenders had a fix.
- The advisory was co-sealed by 16-plus intelligence and cyber agencies from the U.S., Netherlands, Australia, Canada, New Zealand, U.K., and across the EU, reflecting high-confidence allied attribution.
- CISA expects LAUNDRY BEAR to abandon this specific exploit as patching spreads but warns the group will very likely continue targeting ZCS and other Western email systems with new vulnerabilities.
Because the vulnerability was patched in November 2025 and sixteen-plus governments are jointly publishing detailed IOCs and remediation steps, organizations that act on this advisory can rapidly close the door on the current campaign and use the shared hunting guidance to evict any intruders already inside.
The view-based exploit required no user interaction, ran undetected for months before a patch, and was already used to exfiltrate 90 days of email and address books — meaning many organizations may already be compromised, and the authoring agencies expect LAUNDRY BEAR to quickly pivot to the next novel flaw in Zimbra or a similar platform.



