U.S. and allied cyber agencies warned Thursday that Zimbra Russia attacks tied to the state-aligned group Laundry Bear have hit government and commercial organizations across the West, after first focusing heavily on Ukrainian targets.
The joint advisory from agencies in the United States, United Kingdom, Europe, Australia and New Zealand said the campaign abuses Zimbra Collaboration Suite webmail through CVE-2025-66376, a vulnerability Zimbra patched in November 2025. The agencies described the activity as espionage-oriented, citing its stealth, persistence and lack of known financial extortion.
The advisory said Laundry Bear used Ukrainian organizations both as priority targets and as a proving ground before expanding against U.S. and NATO-linked organizations. That pattern tracks a familiar Russian playbook: try the technique where the Kremlin already has operational interest, then reuse what works elsewhere.
What is the Zimbra vulnerability used in the Russia-linked attacks?
CVE-2025-66376 is a Zimbra webmail flaw that the attackers exploited through malicious emails. According to the advisory, the payload can run when a victim opens the message, which makes the phishing effectively zero-click once the email lands in the inbox.
The agencies said Laundry Bear has used the exploit since at least July 2025. The malicious JavaScript is embedded in messages sent from accounts the attackers had already taken over, a detail that matters because mail from a real account is more likely to survive both human suspicion and automated filtering.
Once inside an account, the group tried to collect the previous 90 days of email, passwords, contact lists, two-factor authentication tokens and other passcodes, according to the advisory. That is not smash-and-grab ransomware behavior. It is the sort of mailbox looting that makes sense if the objective is intelligence collection, lateral access or both.
Palo Alto Networks’ Unit 42 also published research Thursday on the same campaign. Unit 42 said the attackers went after defense and transportation organizations, along with financial institutions in NATO countries, Ukraine, Commonwealth of Independent States countries and Africa.
Proofpoint, in a separate advisory, said the group compromised U.S. targets in government, high science and the defense industrial base. Its researchers said the campaign fits a broader pattern of Russian and Belarusian operators using cross-site scripting against webmail systems to harvest messages.
Dutch intelligence agencies publicly identified Laundry Bear in May 2025 and linked it to intrusions in the Netherlands, including an attack on the national police. Microsoft has said the group has been active since at least 2024. Earlier Laundry Bear operations used less refined methods, including password spraying and phishing that depended on a user clicking a link.
The attribution picture is messy, as usual. Seqrite reported in March 2026 on a Zimbra zero-click campaign that compromised a Ukrainian maritime agency and assessed with medium confidence that Fancy Bear was responsible. Dutch intelligence has said Laundry Bear’s methods overlap with Fancy Bear’s, while treating them as separate actors.
The practical guidance is less ambiguous. The government agencies urged organizations running Zimbra webmail to install the available patch immediately. If they cannot patch, the agencies said they should move users to another mail client rather than leave the vulnerable path exposed.
This story draws on original reporting from The Record.