Russian Hackers Exploit Zimbra Zero-Click Flaw for Email Theft
laundry bearzimbracve-2025-66376russian hackerszero-click exploitmfa bypasscybersecurityemail theftstate-sponsored hackingnatoukrainepatching

Russian Hackers Exploit Zimbra Zero-Click Flaw for Email Theft

The Incident: A Quiet Campaign Goes Loud

Russian state-aligned hackers, identified as Laundry Bear by Dutch intelligence in May 2025, have been tracked since at least 2024 by Microsoft. They have been exploiting a critical Zimbra zero-click flaw (CVE-2025-66376) since at least 2024. This sophisticated zero-click exploit, which emerged in July 2025, specifically targets Zimbra webmail users, allowing for silent email theft and MFA bypass. While the vulnerability was patched in November 2025, attacks continued, highlighting the persistent threat. In March 2026, cybersecurity firm Seqrite documented a similar zero-click phishing campaign still impacting Zimbra webmail users, though Seqrite attributed this activity to Fancy Bear with medium confidence. Dutch intelligence, however, states that Laundry Bear's tactics, while overlapping, point to a distinct actor. The ability of this Zimbra zero-click flaw to bypass traditional security measures makes it particularly insidious.

On July 23, 2026, federal agencies across the U.S., U.K., Europe, Australia, and New Zealand issued a joint warning regarding this activity. Palo Alto Networks' Unit 42 simultaneously released a detailed report, confirming the campaign's scope. While this threat isn't new, the recent coordinated international alert highlights its persistent and widespread risk to many organizations, emphasizing the urgent need to address the Zimbra zero-click flaw.

Laundry Bear has a history of using password spraying and traditional phishing. However, this zero-click method is far stealthier and more effective. It's designed specifically to steal sensitive information for intelligence purposes, leveraging the Zimbra zero-click flaw for maximum impact.

How a Malicious Email Became a Backdoor: Understanding the Zimbra Zero-Click Flaw

The attack exploits CVE-2025-66376, a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite's Classic UI. This flaw permits an attacker to inject malicious JavaScript directly into a web page, forming the core of the Zimbra zero-click flaw.

Here's how the attack chain unfolds:

First, attackers craft an email containing a hidden JavaScript payload – a classic spearphishing tactic (MITRE ATT&CK T1566.002). The real danger is that simply opening this email in a vulnerable Zimbra webmail client immediately executes the malicious JavaScript. No user interaction, clicks, or downloads are required, making this Zimbra zero-click flaw particularly dangerous.

This malicious JavaScript then scrapes sensitive data from the active webmail session, including up to 90 days of emails, contact lists, and potentially passwords.

Crucially, while many organizations rely on MFA, Laundry Bear's method circumvents it. The malicious JavaScript exfiltrates two-factor authentication (2FA) tokens and other passcodes, allowing attackers to bypass the user's primary 2FA and establish persistent access to the compromised account. This is a direct bypass of multi-factor authentication, consistent with MITRE ATT&CK T1550.002 (Bypass Multi-Factor Authentication: Application Passwords).

It's a common misconception that MFA provides absolute protection; attackers are constantly finding ways to generate new tokens or bypass it at different layers.

The objective extends beyond a one-time data theft. By exfiltrating application passcodes, attackers establish a persistent foothold, maintaining access even if the user changes their primary password.

Screenshot of Zimbra webmail showing a successful XSS injection from the Zimbra zero-click flaw
Screenshot of Zimbra webmail showing a successful XSS

Who's Getting Hit, and Why It Matters: The Global Impact of the Zimbra Zero-Click Flaw

Laundry Bear's targeting profile is consistent with espionage, showing no indicators of financial motivation. The widespread exploitation of the Zimbra zero-click flaw underscores its value to state-sponsored actors.

Ukrainian entities initially served as a 'testbench' for Laundry Bear's techniques, a standard practice for state-sponsored groups who refine methods against high-value, high-conflict targets before broader deployment.

The campaign subsequently expanded to include:

  • U.S. and NATO organizations.
  • Defense, transportation, and financial sectors within NATO member states, Ukraine, Commonwealth of Independent States (CIS) countries, and Africa (Palo Alto Networks’ Unit 42).
  • Government, high science, and defense industrial base targets in the United States (Proofpoint).
  • National police forces, such as those in the Netherlands (Dutch intelligence).
  • A Ukrainian maritime agency (according to Seqrite).

The zero-click nature and MFA bypass capabilities of this exploit have sparked considerable concern among security researchers and defenders. The practical implication is that merely viewing an email can lead to deep compromise. The exploitation of CVE-2025-66376 as a zero-day for months before its November 2025 patch underscores the persistent risk for any organization that has not yet applied this critical update, making the Zimbra zero-click flaw a top-tier threat.

Ultimately, this isn't just about stealing data; it's a clear move for strategic intelligence gathering, highlighting the geopolitical motivations behind Laundry Bear's operations.

What We Do Now: Proactive Defense Against the Zimbra Zero-Click Flaw

If your organization uses Zimbra webmail, your absolute top priority right now is to **patch your software**. CVE-2025-66376 was addressed in November 2025. Failure to apply this update leaves systems vulnerable to this zero-click attack, allowing Russian hackers to exploit the Zimbra zero-click flaw for persistent access. Ensure your patching process includes thorough testing to prevent service disruption, but prioritize this critical update immediately.

If patching is not immediately feasible due to complex environments or legacy systems, direct employees to use an alternative mail client. While this offers a temporary workaround, it's not a sustainable long-term fix and should only be considered a stop-gap measure until the patch can be deployed.

This incident underscores a critical point: MFA, while essential, does not offer complete protection. Attackers will consistently seek bypass methods. To counter sophisticated threats like the Zimbra zero-click flaw, consider the following practical mitigations:

  • **Enhanced Monitoring and Threat Hunting:** Implement robust logging and monitoring for unusual activity within your Zimbra environment. Look for suspicious JavaScript execution, unexpected API calls, or unusual data exfiltration patterns. Integrate threat intelligence feeds related to Laundry Bear and similar state-sponsored actors to proactively identify indicators of compromise (IoCs).
  • **Network Segmentation:** Isolate your Zimbra infrastructure from other critical internal systems. This limits the potential for lateral movement should an attacker successfully exploit the zero-click vulnerability and gain a foothold.
  • **User Education and Awareness:** Conduct regular training sessions for employees, explaining the nuances of zero-click attacks and spearphishing. Emphasize that even without clicking, simply opening an email can be dangerous in vulnerable systems.
  • **Incident Response Planning:** Develop and regularly test a specific incident response plan for email system compromises. This plan should detail steps for containment, eradication, recovery, and post-incident analysis, especially concerning the exfiltration of sensitive data via the Zimbra zero-click flaw.
  • **Regular Security Audits:** Conduct frequent vulnerability assessments and penetration tests on your webmail infrastructure. This helps identify and remediate potential weaknesses before they can be exploited by adversaries.
  • **Implement Zero Trust Principles:** Apply the principle of least privilege to all user and system access within your Zimbra environment. Verify every access request, regardless of whether it originates inside or outside the network.
Security Operations Center monitoring for threats after a Zimbra zero-click flaw exploit
Security Operations Center monitoring for threats after

The Bottom Line

Laundry Bear's exploitation of CVE-2025-66376 in Zimbra exemplifies sophisticated state-sponsored espionage. The zero-click execution, coupled with the ability to bypass MFA via exfiltrated application passcodes, significantly elevates the threat. Organizations running Zimbra should operate under the assumption of being a target and respond proactively. Patching isn't just a recommendation; it's the *only* way to truly close this specific attack vector.

Daniel Marsh
Daniel Marsh
Former SOC analyst turned security writer. Methodical and evidence-driven, breaks down breaches and vulnerabilities with clarity, not drama.