LAUNDRY BEAR Exploits Zero-Day in Zimbra Collaboration Suite, Targets Western Governments and Businesses
A Russian state-supported APT group, tracked as **LAUNDRY BEAR**, has been actively compromising Western government and commercial organizations since July 2025. The group leveraged a previously unknown zero-day vulnerability, **CVE-2025-66376**, in the **Zimbra Collaboration Suite (ZCS)** to covertly exfiltrate sensitive email data and establish persistent access.
A sophisticated Russian state-supported advanced persistent threat (APT) group, widely known as **LAUNDRY BEAR** (also tracked as **Void Blizzard**, **CL-STA-1114**, and **TA488**), has been targeting and compromising Western government and commercial entities. Their primary objective: the clandestine acquisition of sensitive email data.
### Evolution of Tactics
Historically, **LAUNDRY BEAR** relied on less sophisticated initial access methods such as password spraying, phishing, and pass-the-cookie attacks. These techniques allowed them to conduct high-volume operations with considerable success. However, their latest campaign against **Zimbra Collaboration Suite (ZCS)** users marks a significant shift towards more advanced capabilities.
### The Zero-Day Exploit: CVE-2025-66376
The current campaign leverages a novel exploit for a zero-day vulnerability, identified as **CVE-2025-66376**. This critical vulnerability was actively exploited before a patch became available in November 2025.
Unlike traditional phishing that requires user interaction (e.g., clicking a link), this exploit is 'view-based.' Simply viewing a malicious email within a vulnerable version of the **ZCS** webmail service is enough to trigger the exploit.
Once triggered, the exploit attempts to exfiltrate a victim's last 90 days of email communications, the organization's Global Address List (GAL), and other sensitive information to **LAUNDRY BEAR**-controlled servers. It also endeavors to establish persistent access to compromised accounts through various means.
### International Warning and Mitigation
This ongoing threat has prompted a joint Cybersecurity Advisory (CSA) from a coalition of international intelligence and cybersecurity agencies. These include the **United States National Security Agency (NSA)**, **Federal Bureau of Investigation (FBI)**, **Cybersecurity and Infrastructure Security Agency (CISA)**, **Netherlands Defence Intelligence and Security Service (MIVD)**, **Netherlands General Intelligence and Security Service (AIVD)**, and numerous other partners from Australia, Canada, New Zealand, the UK, and across Europe.
Organizations are strongly urged to update their **ZCS** software immediately and implement additional mitigations to counter this persistent threat. The advisory provides specific remediations for those who discover the presence of the listed Indicators of Compromise (IOCs).
### Persistent Threat Landscape
While patching **CVE-2025-66376** may lead **LAUNDRY BEAR** to discontinue this specific campaign, the group's history suggests they will continue to target **ZCS** and other email systems in Western countries. It is highly probable they will continue to exploit novel vulnerabilities and employ social engineering when necessary. Regular software updates and continuous monitoring of email systems for malicious activity are paramount for defense.
### Downloadable Indicators of Compromise (IOCs)
For a detailed list of IOCs, cybersecurity professionals can access:
* [AA26-204A.stix.xml](https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml) (STIX XML)
* [AA26-204A.stix.json](https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json) (STIX JSON)
### Background: From Simple Phishing to Zero-Day Exploits
Prior advisories from **AIVD**, **MIVD**, and **Microsoft** in May 2025 highlighted **LAUNDRY BEAR**'s malicious activities dating back to April 2024. These earlier campaigns primarily targeted cloud-based email environments, including **Microsoft Exchange**, by abusing legitimate APIs for bulk data exfiltration (**T1114.002**).
Initial access often involved procuring stolen credentials from criminal marketplaces (**T1078**) or using social engineering to lure targets to malicious sites. An example cited was a fake European Defence & Security Summit registration portal that mimicked a **Microsoft** sign-in page. This allowed **LAUNDRY BEAR** to intercept credentials and session tokens using a modified **Evilginx** toolkit, performing Adversary-in-the-Middle (AiTM) attacks (**T1557**).
By July 2025, the group shifted to more technical compromises, deploying a custom capability named "*Π£Π»Π΅ΠΉ*" or "*Ulej*" (Russian for beehive). This tool was specifically designed to exploit **ZCS** (**T1114**) and exfiltrate sensitive user data, including: last 90 days of emails, email addresses, passwords (**T1589.001**), and the Global Address List (GAL) (**T1087**).
This evolution underscores **LAUNDRY BEAR**'s adaptability and increasing technical sophistication in their ongoing efforts to gather intelligence for the Russian Federation.