Russian state-sponsored actor Laundry Bear (Void Blizzard/TA488) has executed a large-scale espionage campaign targeting Zimbra Collaboration Suite (ZCS) versions prior to 10.1.13 and 10.0.18. Exploiting CVE-2025-66376, a stored XSS vulnerability triggered by improper sanitization of CSS @import directives, attackers achieve zero-click code execution when a target views a crafted email. The operation utilizes the 'Ulej' tool for session and 2FA backup code harvesting and the 'Flowerbed' Python framework for data exfiltration via Dockerized infrastructure. Impacted entities include government, defense, and energy sectors, with the loss of 90 days of mailbox content and browser credentials. Immediate patching to ZCS 10.1.13 or 10.0.18 is required.
-
Campaign Overview: Strategic Espionage
- Target sectors: Focuses on the Defense Industrial Base, government agencies, energy, law enforcement, and NGOs.
- Objectives: Long-term intelligence gathering and high-value data exfiltration from Western strategic sectors.
- Timeline: Activity detected since July 2025, with critical security patches released in November 2025.
-
Technical Analysis: CVE-2025-66376 Mechanics
- Vector: Zero-click exploitation via stored XSS utilizing improper sanitization of CSS
@importdirectives within email content. - Payload: Deploys Base64-encoded and XOR-encrypted JavaScript to bypass traditional security filters.
- Trigger: Malicious code executes automatically upon the victim viewing the specially crafted email in the ZCS webmail client.
- Vector: Zero-click exploitation via stored XSS utilizing improper sanitization of CSS
-
Malware Toolset: Ulej and Flowerbed
- Ulej: A web-based tool used to harvest session tokens, browser-saved passwords, and 2FA backup scratch keys.
- Flowerbed: A Python-based exfiltration framework leveraging Docker containers including Catcher (aggregation), Certbot (SSL), Nginx (reverse proxy), and Gardener.
- Capability: Automates the theft of the Global Address List (GAL) and the most recent 90 days of mailbox communications.
-
Network Indicators & Detection
- Infrastructure: Heavy utilization of Mullvad VPN and unfamiliar VPS providers to mask C2 traffic.
- Traffic Patterns: Detection of unusual DNS queries featuring random subdomains and HTTPS-based exfiltration channels.
- Authentication Bypass: Capability to circumvent MFA by stealing backup codes directly from the user's local browser environment.
-
Mitigation & Defensive Response
- Patching: Immediate update of Zimbra Collaboration Suite (ZCS) to versions 10.1.13 or 10.0.18.
- Auditing: Review of outbound HTTPS traffic to known VPN exit nodes and suspicious VPS IP ranges.
- Remediation: Force rotation of 2FA backup codes and application passwords for all high-privilege accounts.
Related posts
- malware-log.hatenablog.com — Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations
- cybersecurity.pk — Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
- Risky Business Newsletters — Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
- Security Affairs — US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
- helpnetsecurity.com — Russian hackers exploit unpatched Zimbra servers to steal emails
- techjacksolutions.com — Laundry Bear Chains Phishing With Zimbra Zero-Click Vulnerability to Conduct Large-Scale Email Theft
- SC Media — Russian hackers exploited Zimbra zero-day in espionage campaigns
- TechNadu — TA488 Half-Click Exploit Moves to Outlook Web Access Flaw, Deploys Persistent OWAReaper Backdoor
- helpnetsecurity.com — Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
- blackhatnews.tokyo
- blackswan-cybersecurity.com — THREAT ADVISORY Russian APT “Laundry Bear” Exploiting OWA XSS for Persistent Mailbox Access August 5, 2026
- thecyberexpress.com — Russian-Linked Hackers Target Zimbra Users With Zero-Day Exploit
- Malware News — Russian hackers can steal government emails without victims clicking a link, cyber agencies warn
- Techcommunity
- Tenable
- Nvd
- Blog
- Socprime
- Cycognito
- CISA All Advisories — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
- unit42.paloaltonetworks.com — Russian Global Webmail Espionage
- CISA RSS — CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity
- The Record by Recorded Future — International alert spotlights Russia-linked attacks on Zimbra webmail
- cyberscoop.com — Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
- computerweekly.com — Russian APT Laundry Bear perfects zero-click phishing attack
- Industrial Cyber — Russian hacker group Laundry Bear exploits Zimbra zero-click flaw to target Western government, critical infrastructure
- computerweekly.com — Laundry Bear pivots to new exploit days after Zimbra alert
- The Record by Recorded Future — Laundry Bear’s webmail hackers had more in store after February, report says
- Safebreach
- Ampcuscyber
- Infosecurity-magazine
- Proofpoint
- Govexec
- Digit
- Ic3
- Socradar
- feeds.feedburner.com — Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
- csoonline.com — Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
- Penligent
- Cve
- Msrc
- Proofpoint
- Infosecurity-magazine
- Connect
- Compudent