LIVE · cybersecurity feed
Live wire
phishing

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]

zeroday.news · 9d ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a Russian state-sponsored hacking group, known as Laundry Bear or Void Blizzard, which is actively exploiting a zero-click vulnerability in Zimbra Collaboration email servers. The group is combining phishing attacks with the exploitation of CVE-2025-66376, a cross-site scripting (XSS) flaw in Zimbra Collaboration Suite's Classic UI.

This vulnerability allows malicious JavaScript embedded in specially crafted HTML emails to execute automatically when a user views the message, without requiring any interaction like clicking a link. CISA confirmed that Laundry Bear exploited this flaw as a zero-day before Zimbra released a patch in November 2025, and the group continues to target organizations running unpatched servers.

The attackers leverage the exploit to automatically collect and exfiltrate sensitive user data, including the last 90 days of emails, email addresses, passwords, Global Address List (GAL), and two-factor authentication (2FA) tokens. To maintain persistent access while bypassing multi-factor authentication (MFA), the group creates and sends back a new Zimbra application passcode, which is used by legacy email clients such as IMAP or ActiveSync that do not support modern TOTP authentication flows.

Exfiltrated information is sent to actor-controlled servers running the group's "Flowerbed" collection framework. Smaller data payloads are encoded and transmitted via DNS A-record queries, while larger data, including entire mailboxes, are uploaded over HTTPS as compressed archives.

In addition to exploiting the Zimbra flaw, Laundry Bear also employs adversary-in-the-middle (AiTM) phishing kits. These kits impersonate legitimate Zimbra login portals to steal credentials and session cookies, thereby gaining unauthorized access to target email accounts. CISA has released Indicators of Compromise (IOCs) that include domain names used in these campaigns, such as 'mailnalysis.com', 'emailanalytics.com.ua', 'zimbrastat.com', 'zimbra-metadata.com', 'istc-cloud.com', and 'zmailanalytics.com'.

The group's targets include a wide range of organizations within the Defense Industrial Base (DIB), federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology sectors. Laundry Bear, which Microsoft tracks as Void Blizzard, has been focused on intelligence collection against entities aligned with Russian strategic interests, primarily targeting NATO member states and Ukraine since at least 2024.

Dutch intelligence agencies first attributed cyberespionage attacks to Laundry Bear in May 2025, linking them to a 2024 compromise of the Dutch National Police that exposed personnel information. Microsoft has also documented successful compromises of organizations supporting Ukraine, including those in the defense, transportation, and aviation sectors. Earlier campaigns by Laundry Bear have involved charity-themed phishing emails to deliver malware to Ukraine's military.

CISA recommends that organizations using Zimbra update their software to the latest version, review published indicators of compromise, and investigate systems for connections to identified malicious domains and IP addresses. Furthermore, organizations should monitor for suspicious authentication activity, revoke any unauthorized application passcodes (especially those with the 'ZimbraWeb' designation), review accounts for unauthorized mailbox access, and implement phishing-resistant multi-factor authentication where possible.

phishingvulnerabilitypatchnation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]