
criticalState Cyber Warfare
CISA and Global Partners Alert on Russian 'Laundry Bear' Zero-Click Attacks Targeting Western Zimbra Webmail Users
A joint advisory warns that Russian state-sponsored actor Laundry Bear is exploiting a zero-click vulnerability in Zimbra webmail to exfiltrate sensitive data from Western government sectors.
24 July 2026Last updated 20 August 20265 min readCISA / NSA / FBI Joint Advisory
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global (West/NATO)
- Confidence:
- High Confidence
- CVE:
- CVE-2025-66376
- Source:
- CISA / NSA / FBI Joint Advisory
- Read Time:
- 5 min
Executive Summary On July 23, 2026, the Cybersecurity and Infrastructure Security Agency (CISA), in coordination with the FBI, NSA, and international partners from the UK, Netherlands, Australia, and New Zealand, released a comprehensive joint advisory regarding ongoing malicious activity by the Russian state-supported threat actor known as 'Laundry Bear' (also tracked as Void Blizzard and UAC-0190). Since at least July 2025, this actor has conducted a wide-ranging espionage campaign targeting Western government, defense, and commercial organizations. The primary vector involves the exploitation of a critical vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform, allowing for the covert acquisition of sensitive email data, contact lists, and authentication tokens without requiring any user interaction. ## Threat Analysis Laundry Bear's operations represent a significant evolution in Russian cyber-espionage tactics, prioritizing persistent access and high-volume data collection. Unlike traditional phishing campaigns that rely on social engineering to entice a user into clicking a link or downloading a malicious attachment, the current campaign utilizes a 'zero-click' exploit. This means an account can be compromised simply by the user viewing a malicious email within a vulnerable version of the ZCS web interface. The targeting has been extensive, initially focusing on Ukrainian maritime and government entities before expanding to NATO member states and other Western allies. The group's primary objective is the exfiltration of the last 90 days of communications from compromised accounts, which provides the Russian Federation with strategic intelligence on Western diplomatic and military activity. ## Technical Details The campaign leverages CVE-2025-66376, a vulnerability in ZCS that stems from improper sanitization of Cascading Style Sheet (CSS) @import directives within the email rendering engine. The exploit, internally referred to by researchers as 'Beehive,' allows for the execution of a malicious JavaScript payload when the email is opened. Once the payload is active, it deploys a custom-developed data exfiltration tool named 'Ulej.' Ulej is designed to aggregate email data, passwords, and two-factor authentication (2FA) tokens, subsequently exfiltrating the stolen information to actor-controlled infrastructure. Data exfiltration often utilizes legitimate cloud storage providers to blend in with routine network traffic, making detection difficult for standard security monitoring tools. ## Attribution Assessment Intelligence agencies from the Netherlands (AIVD and MIVD), along with Microsoft and other private sector partners, attribute this activity with high confidence to a Russian state-supported actor. While Laundry Bear's tactics and targets frequently overlap with the GRU-linked group APT28 (Fancy Bear), Dutch intelligence identifies them as a distinct operational unit. The campaign's focus on Western government entities, its use of custom malware like Ulej, and the strategic timing of its expansion align perfectly with the Russian Federation's geopolitical interests and long-term intelligence requirements. ## Implications The move toward zero-click exploits in nation-state espionage significantly lowers the defensive efficacy of traditional user-awareness training. The scale of the Laundry Bear campaign suggests a highly industrialized approach to data theft. For organizations in the defense and government sectors, the compromise of Zimbra servers could lead to the exposure of classified projects, personnel records, and strategic communications. Furthermore, the ability to steal 2FA tokens could facilitate lateral movement into more secure environments, posing a threat to the integrity of entire organizational networks. ## Recommendations Organizations utilizing the Zimbra Collaboration Suite are urged to immediately update to the latest patched version to mitigate CVE-2025-66376. If immediate patching is not possible, organizations should consider migrating sensitive users to alternative mail clients or disabling the web-based mail interface in favor of secure desktop clients. Security teams should scan for indicators of compromise (IOCs) associated with the Ulej toolkit and monitor for unusual outbound traffic to known cloud storage providers. Implementing a robust Zero Trust architecture and enforcing hardware-based security keys can also provide significant protection against the credential and token theft techniques employed by Laundry Bear.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News Room