Russian state-supported threat actors tracked as LAUNDRY BEAR have exploited a former zero-day flaw in Zimbra Collaboration Suite ZCS webmail to steal up to 90 days of email communications, credentials, and corporate directory data from targeted organizations.
The activity, detailed in a joint cybersecurity advisory released on July 23, 2026, has targeted Western government and commercial entities since at least July 2025.
The campaign affected organizations in the defense industrial base, government, energy, education, law enforcement, media, non-governmental, and technology sectors.
Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day
LAUNDRY BEAR, also tracked by parts of the cybersecurity industry as Void Blizzard, CL-STA-1114, and TA488, is assessed to operate in support of Russian intelligence interests. The group’s operations appear focused on covert intelligence gathering rather than financial extortion.

The campaign abuses CVE-2025-66376, a cross-site scripting XSS vulnerability caused by improper sanitization of Cascading Style Sheets CSS @import directives in vulnerable Zimbra webmail versions.
Synacor patched the issue in November 2025, although the vulnerability was publicly assigned and published in January 2026.
Unlike conventional phishing attacks, the malicious email requires no link click, attachment download, or credential submission. Simply viewing the crafted email through a vulnerable Zimbra webmail interface can trigger embedded JavaScript.
The payload is hidden in an SVG element’s onload field and uses Base64 encoding combined with XOR encryption to obscure its final data-collection script.
Attackers can alter encryption keys and insert non-functional @import statements, enabling rapid payload variation and evasion of basic signature-based detection.
CISA said the exploit initially functioned as a zero-day because LAUNDRY BEAR began using it months before a vendor patch was released.
The campaign highlights the group’s shift from password spraying, credential theft, and adversary-in-the-middle phishing toward more technically capable email-platform exploitation.
LAUNDRY BEAR uses a custom capability named Ulej, Russian for “beehive,” to collect and exfiltrate victim information. Once executed, the malware runs through 12 asynchronous stages, harvesting the victim’s email address, Zimbra version, current webmail URL, device information, OAuth consumer details, Global Address List GAL, and email archives.
The malware attempts to retrieve every non-junk message sent or received during the previous 90 days. It queries each day individually, compresses retrieved messages into GZIP archives, and sends them to attacker-controlled infrastructure.
The operation also seeks to establish durable mailbox access. It tries to enable IMAP, create a Zimbra Application Passcode called “ZimbraWeb,” collect scratch codes used for two-factor authentication recovery, and extract passwords automatically entered by browser password managers through hidden login fields.

Collected information is sent to the group’s Flowerbed framework, a Docker-based infrastructure deployed on short-lived virtual private servers.
Flowerbed uses Catcher, Certbot, Nginx, and Gardener containers to receive, encrypt, aggregate, and monitor stolen data. The actors use both HTTPS and DNS-based exfiltration, allowing sensitive metadata to leave a victim environment.
Mitigation
Organizations running Zimbra should immediately identify and patch exposed systems against CVE-2025-66376. Security teams should also review mail logs and outbound DNS requests for suspicious encoded subdomains.
Administrators should reset credentials and revoke active sessions for potentially affected accounts, rotate two-factor recovery codes, review mailbox delegation and OAuth configurations, and block the indicators of compromise published in CISA’s STIX feeds.
Continuous monitoring of webmail activity remains essential, as LAUNDRY BEAR is likely to continue targeting Zimbra and other email platforms used by Western organizations.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.