Cybersecurity agencies from the United States, United Kingdom, Europe, Australia, and New Zealand have issued a joint alert regarding a series of zero-click phishing attacks targeting Zimbra Collaboration Suite webmail. These attacks, attributed to the Russian state-aligned advanced persistent threat (APT) group known as Laundry Bear, exploit a vulnerability, CVE-2025-66376, which was patched in November 2025.
The campaign initially focused extensively on Ukrainian entities before expanding to target organizations in the U.S. and NATO member states. This pattern suggests a strategy by Russian cyber threat groups to use Ukrainian targets as a testing ground for malicious techniques before broader global deployment. The covert and persistent nature of the activity, coupled with the absence of financial extortion, strongly indicates an espionage objective supported by the Russian government.
Palo Alto Networks' Unit 42 reported that the hackers have targeted the defense, transportation, and financial sectors within NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Separately, Proofpoint stated that the group has compromised government, high science, and defense industrial base targets in the United States.
Laundry Bear was first identified in May 2025 by Dutch intelligence agencies, which linked the group to hacks in the Netherlands, including an incident affecting the national police. Microsoft indicates the group has been active since at least 2024. Earlier campaigns by Laundry Bear employed less sophisticated methods, such as password spraying and phishing attempts that required user interaction.
However, since at least July 2025, the group has deployed a novel exploit against CVE-2025-66376. This involves embedding a malicious JavaScript payload within emails sent from previously compromised accounts. The payload executes immediately upon the recipient opening the email, requiring no further action from the user.
Once an account is compromised, the attackers attempt to exfiltrate sensitive data, including the last 90 days of emails, passwords, contact lists, two-factor authentication tokens, and other passcodes.
In March 2026, the cybersecurity firm Seqrite described a zero-click phishing campaign exploiting Zimbra webmail that compromised a Ukrainian maritime agency, attributing this activity with medium confidence to the Russian APT known as Fancy Bear. While Dutch intelligence notes an overlap in tactics between Laundry Bear and Fancy Bear, they consider them distinct actors. Proofpoint researchers have observed this campaign as consistent with other recent activities by Russian and Belarusian hackers utilizing cross-site scripting exploits to compromise webmail servers.
Organizations using Zimbra webmail services are urged to immediately apply the November 2025 patch for CVE-2025-66376. If patching is not immediately feasible, agencies recommend directing employees to use an alternative mail client to mitigate the risk of compromise.






