FILTERING BY: CLEAR FILTER

Laundry Bear Leverages Zimbra Zero-Click Vulnerabilities for Large-Scale Espionage

Russian state-sponsored threat actor Laundry Bear (TA488) has executed a sophisticated espionage campaign targeting Western military and government entities via zero-click/half-click exploits in the Zimbra Collaboration Platform. By utilizing JavaScript injection within phishing emails, the actor achieves credential theft and persistent mail server access without requiring user interaction beyond opening the email. This exploitation window spanned approximately five months prior to the July 2025 patch. The campaign has since transitioned to include Microsoft Outlook Web Access (OWA) exploitation, facilitating continued large-scale email interception and sensitive data exfiltration.


LINK COPIED TO CLIPBOARD