A Russian state-sponsored group, known as Laundry Bear, has been targeting organizations with a zero-click exploit that can compromise email accounts without the need for a click. The attack targets organizations running unpatched versions of the Zimbra Collaboration Suite, which is an email and collaboration platform used by some governments, schools, businesses, and other organizations.
How the Attack Works
The attack uses a security flaw known as CVE-2025-66376, which is a cross-site scripting vulnerability that affects the Classic user interface in certain versions of the Zimbra Collaboration Suite. When a vulnerable Zimbra webmail client displays a specially crafted HTML email, the malicious code runs automatically, allowing the attackers to collect passwords, authentication data, and up to 90 days of email messages.
The attackers can also collect the target’s email address and password, as well as the organization’s Global Address List, which can be used to impersonate a trusted coworker or identify more valuable accounts. The attack can also create a new Zimbra application passcode, which can be used to gain access to the email account even after the main account password has been changed.
Indicators of Compromise
CISA has identified several indicators of compromise, including domains that impersonate Zimbra infrastructure, such as mailnalysis.com, zimbrastat.com, zimbra-metadata.com, and zmailanalytics.com. Organizations should review CISA’s complete list of indicators of compromise to determine if they have been targeted.
Laundry Bear has been linked to several high-profile breaches, including a 2024 breach of the Dutch National Police, which exposed personal information belonging to police personnel. The group has also targeted organizations connected to Russian strategic interests, including NATO member states and groups supporting Ukraine.
Original reporting: Fox News (HLL/CB) — read the source article.