Russian State-Sponsored Group 'Laundry Bear' Exploits Zimbra Flaw and AiTM Phishing
The Russian state-sponsored hacking group **Laundry Bear**, also known as **Void Blizzard**, is actively targeting organizations using **Zimbra Collaboration** email servers. Their campaign combines sophisticated phishing tactics with the exploitation of a now-patched cross-site scripting (XSS) vulnerability, **CVE-2025-66376**, to steal sensitive data and maintain persistent access.

**CISA** has issued a stark warning regarding the activities of **Laundry Bear**, a Russian state-sponsored hacking group. The group is leveraging a multi-pronged attack strategy against organizations utilizing **Zimbra Collaboration** email servers, focusing on phishing and exploiting a critical vulnerability.
### Broad Targeting Across Critical Sectors
**Laundry Bear**'s targets are diverse and strategically significant, encompassing organizations within the **Defense Industrial Base (DIB)**, federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology sectors.
### Exploiting CVE-2025-66376
Central to their operations is the exploitation of **CVE-2025-66376**, a cross-site scripting (XSS) vulnerability found in **Zimbra Collaboration Suite**'s Classic UI. This flaw allows malicious JavaScript embedded in specially crafted HTML emails to execute automatically when a victim views the message. Crucially, this attack vector does not require user interaction, such as clicking a link, to compromise an account.
**CISA** confirmed that **Laundry Bear** exploited this flaw as a zero-day before **Zimbra** released a patch in November 2025. Unpatched servers remain vulnerable, and the group continues to actively target them.
### Data Exfiltration and Persistence
Upon successful exploitation, **Laundry Bear** automatically collects a victim's last 90 days of emails, email address, password, Global Address List (GAL), and two-factor authentication (2FA) tokens. To maintain persistent access while bypassing MFA, attackers also generate and utilize a new **Zimbra** application passcode, designed for legacy email clients like IMAP or ActiveSync.
Exfiltrated data is routed to actor-controlled servers running the group's custom "Flowerbed" collection framework. Smaller data packets are encoded and transmitted via DNS A-record queries, while larger payloads, including mailbox data, are uploaded as compressed archives over HTTPS.
### Adversary-in-the-Middle (AiTM) Phishing
Beyond the **Zimbra** vulnerability, **Laundry Bear** also employs sophisticated adversary-in-the-middle (AiTM) phishing kits. These kits impersonate legitimate **Zimbra** login portals to steal credentials and session cookies, thereby gaining unauthorized access to target email accounts.
**CISA**'s Indicators of Compromise (IOCs) reveal the use of deceptive domain names mimicking **Zimbra** infrastructure, including 'mailnalysis.com', 'emailanalytics.com.ua', 'zimbrastat.com', 'zimbra-metadata.com', 'istc-cloud.com', and 'zmailanalytics.com'.
### CISA Recommendations for Organizations
To mitigate the risks posed by **Laundry Bear**, **CISA** recommends that organizations using **Zimbra**:
* Update to the latest software version to install all available security patches.
* Review the published indicators of compromise.
* Investigate systems for connections to identified malicious domains and IP addresses.
* Monitor for suspicious authentication activity.
* Revoke any unauthorized application passcodes, particularly those with the 'ZimbraWeb' designation.
* Review accounts for any unauthorized mailbox access.
Additionally, **CISA** strongly advises implementing phishing-resistant multi-factor authentication where feasible.
### Laundry Bear's History and Targets
The **Laundry Bear** hacking group was first publicly attributed to cyberespionage activities in May 2025 by Dutch intelligence agencies. They linked the group to a 2024 compromise of the **Dutch National Police**, which exposed personal information of police personnel.
**Microsoft** tracks this same group under the name **Void Blizzard**. Since at least 2024, their focus has been intelligence collection against entities aligned with Russian strategic interests, primarily targeting **NATO** member states and Ukraine.
**Microsoft** has documented successful compromises against organizations supporting Ukraine, including those in the defense, transportation, and aviation sectors. Earlier this year, reports also surfaced of a separate **Laundry Bear** campaign targeting Ukraine's military with charity-themed phishing emails delivering malware disguised as donation requests.