News Room
16
Share
Global Advisory Warns of Russian 'Laundry Bear' Zero-Click Campaign Targeting Western Government Email Platforms
criticalState Cyber Warfare

Global Advisory Warns of Russian 'Laundry Bear' Zero-Click Campaign Targeting Western Government Email Platforms

International agencies have exposed a Russian espionage operation using a novel zero-click exploit, Beehive, to bypass user interaction and exfiltrate data from Zimbra mail servers.

26 July 2026Last updated 20 August 20265 min readCISA and NCSC Joint Advisory
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
State Cyber Warfare
Severity:
Critical
Actor Type:
Nation-State
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2025-66376
Source:
CISA and NCSC Joint Advisory
Read Time:
5 min

Executive Summary

On July 24, 2026, the United Kingdom’s National Cyber Security Centre (NCSC), alongside the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and other Five Eyes partners, issued a critical joint advisory regarding a high-sophistication espionage campaign. The operation, attributed to the Russian state-sponsored actor known as "Laundry Bear" (also tracked as Void Blizzard), utilizes a novel zero-click exploit to compromise Zimbra Collaboration Suite (ZCS) platforms. The campaign has successfully targeted defense, energy, government, and law enforcement sectors across North America and Europe, focusing on the covert acquisition of sensitive email data and credentials.

Threat Analysis

Laundry Bear has demonstrated a significant evolution in its tactical approach. While the group previously relied on traditional social engineering, such as password spraying and cookie theft, the current campaign marks a pivot toward highly technical, automated exploitation. Since July 2025, the group has been observed deploying a sophisticated data exfiltration toolset dubbed "Ulej." Intelligence suggests that the codebase for this operation was likely generated with the assistance of advanced AI tools, allowing the actors to create a simple yet highly effective delivery mechanism. The threat is particularly potent because it requires no user interaction (zero-click), meaning victims do not need to click links or download attachments for the compromise to occur.

Technical Details

The campaign leverages a critical vulnerability, CVE-2025-66376, which resides in the way Zimbra handles Cascading Style Sheet (CSS) @import directives. The exploit involves a view-based JavaScript payload embedded within an email's CSS. When a user simply views the malicious email in a vulnerable version of the ZCS webmail client, the improperly sanitized @import directive allows the execution of arbitrary JavaScript. This script then facilitates the bulk exfiltration of the victim's last 90 days of communications, including 2FA tokens and account metadata. The use of AI in generating the 'Beehive' (or Ulej) codebase indicates a streamlined production of exploits that bypass traditional perimeter defenses and user training.

Attribution Assessment

With high confidence, the NCSC and international partners attribute this activity to the Russian Federation's intelligence services. The attribution is based on infrastructure overlaps with previous SVR-linked campaigns and the specific targeting of strategic Western entities. The Netherlands General Intelligence and Security Service (AIVD) originally coined the name Laundry Bear, noting that the group's objective is almost certainly the collection of strategic intelligence to support Russian geopolitical interests. The transition to zero-click exploits reflects a state-level investment in offensive R&D designed to maintain long-term, silent persistence in high-value networks.

Implications

The success of the Laundry Bear campaign underscores the diminishing efficacy of 'human firewall' strategies. Because the exploit bypasses user interaction, traditional security awareness training offers no defense against this specific vector. The compromise of Western government and defense email systems provides Moscow with deep insights into policy deliberations, military readiness, and technological research. Furthermore, the ability of state actors to leverage AI for rapid exploit development suggests a shortening window between vulnerability discovery and weaponization, placing an unprecedented burden on patch management cycles.

Recommendations

Encrygma Intelligence recommends that organizations immediately update all Zimbra Collaboration Suite instances to the latest patched version to mitigate CVE-2025-66376. In addition to patching, network defenders should:

  1. Monitor mail service logs for suspicious CSS @import patterns and unauthorized JavaScript execution.
  2. Implement hardware-based MFA (e.g., FIDO2 keys) to prevent the reuse of stolen 2FA tokens.
  3. Conduct retrospective threat hunting for the 'Ulej' and 'Beehive' indicators of compromise (IOCs) provided in the joint agency advisory.
  4. Adopt a defense-in-depth architecture that includes robust endpoint detection and response (EDR) to identify post-exploitation lateral movement.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo