The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a Russian state-sponsored hacking group, known as Laundry Bear or Void Blizzard, which is actively exploiting a zero-click vulnerability in Zimbra Collaboration email servers. The group is combining phishing attacks with the exploitation of CVE-2025-66376, a cross-site scripting (XSS) flaw in Zimbra Collaboration Suite's Classic UI.
This vulnerability allows malicious JavaScript embedded in specially crafted HTML emails to execute automatically when a user views the message, without requiring any interaction like clicking a link. CISA confirmed that Laundry Bear exploited this flaw as a zero-day before Zimbra released a patch in November 2025, and the group continues to target organizations running unpatched servers.
The attackers leverage the exploit to automatically collect and exfiltrate sensitive user data, including the last 90 days of emails, email addresses, passwords, Global Address List (GAL), and two-factor authentication (2FA) tokens. To maintain persistent access while bypassing multi-factor authentication (MFA), the group creates and sends back a new Zimbra application passcode, which is used by legacy email clients such as IMAP or ActiveSync that do not support modern TOTP authentication flows.
Exfiltrated information is sent to actor-controlled servers running the group's "Flowerbed" collection framework. Smaller data payloads are encoded and transmitted via DNS A-record queries, while larger data, including entire mailboxes, are uploaded over HTTPS as compressed archives.
In addition to exploiting the Zimbra flaw, Laundry Bear also employs adversary-in-the-middle (AiTM) phishing kits. These kits impersonate legitimate Zimbra login portals to steal credentials and session cookies, thereby gaining unauthorized access to target email accounts. CISA has released Indicators of Compromise (IOCs) that include domain names used in these campaigns, such as 'mailnalysis.com', 'emailanalytics.com.ua', 'zimbrastat.com', 'zimbra-metadata.com', 'istc-cloud.com', and 'zmailanalytics.com'.
The group's targets include a wide range of organizations within the Defense Industrial Base (DIB), federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology sectors. Laundry Bear, which Microsoft tracks as Void Blizzard, has been focused on intelligence collection against entities aligned with Russian strategic interests, primarily targeting NATO member states and Ukraine since at least 2024.
Dutch intelligence agencies first attributed cyberespionage attacks to Laundry Bear in May 2025, linking them to a 2024 compromise of the Dutch National Police that exposed personnel information. Microsoft has also documented successful compromises of organizations supporting Ukraine, including those in the defense, transportation, and aviation sectors. Earlier campaigns by Laundry Bear have involved charity-themed phishing emails to deliver malware to Ukraine's military.
CISA recommends that organizations using Zimbra update their software to the latest version, review published indicators of compromise, and investigate systems for connections to identified malicious domains and IP addresses. Furthermore, organizations should monitor for suspicious authentication activity, revoke any unauthorized application passcodes (especially those with the 'ZimbraWeb' designation), review accounts for unauthorized mailbox access, and implement phishing-resistant multi-factor authentication where possible.






