
Void Blizzard Targets European Cloud Infrastructure via Critical Zimbra Vulnerability CVE-2025-66376
Recent intelligence confirms Void Blizzard (Laundry Bear) is actively exploiting Zimbra collaboration suites to deploy the 'Ulej' malware framework, facilitating long-term espionage against EU targets.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Europe
- Confidence:
- High Confidence
- CVE:
- CVE-2025-66376
- Source:
- HECAVEX Intelligence
- Read Time:
- 4 min
Executive Summary
On August 14, 2026, new intelligence was released regarding the Russian-affiliated threat actor Void Blizzard (also known as Laundry Bear). The group has intensified its espionage operations against European government and diplomatic entities by exploiting a critical vulnerability in Zimbra collaboration servers (CVE-2025-66376). This campaign utilizes a sophisticated multi-stage infection chain involving the 'Ulej' and 'Flowerbed' malware families to establish persistent access to cloud-based communication environments.
Threat Analysis
Void Blizzard has historically focused on strategic intelligence collection, but recent shifts indicate a move toward cloud-forensic exploitation. According to APT Notes by HECAVEX, the group’s latest activity involves the systematic targeting of edge devices and collaboration platforms. By compromising Zimbra servers, the actor gains direct access to sensitive email traffic and internal documents without needing to compromise individual end-user devices. This "living-off-the-cloud" approach minimizes the footprint of the intrusion and bypasses traditional endpoint detection and response (EDR) solutions.
Technical Details
The campaign leverages CVE-2025-66376, a remote code execution vulnerability in the Zimbra suite. Upon successful exploitation, the attackers deploy a lightweight loader known as 'Flowerbed,' which performs initial reconnaissance and environment validation. If the target is deemed high-value, the loader fetches the 'Ulej' framework. Ulej is a modular espionage toolkit designed for data exfiltration and lateral movement within cloud environments. Technical analysis reveals new forensic anchors, including specific registry keys and temporary file paths used for staging stolen data. The group also utilizes compromised Azure credentials to facilitate data transfer, mirroring techniques seen in other recent enterprise breaches Cyber Press.
Attribution Assessment
We assess with high confidence that this campaign is the work of Void Blizzard, a cluster of activity closely associated with Russian military intelligence (GRU). The attribution is based on the overlap in command-and-control (C2) infrastructure and the use of proprietary malware previously linked to GRU Unit 74455 APT Notes by HECAVEX. The timing of the campaign aligns with broader Russian strategic interests in monitoring European diplomatic responses to ongoing regional conflicts.
Implications
The exploitation of collaboration platforms like Zimbra poses a severe risk to digital sovereignty. As organizations migrate to cloud-integrated suites, the concentration of sensitive data makes these platforms prime targets for state-sponsored espionage. The ability of Void Blizzard to remain undetected while exfiltrating large volumes of data suggests a high level of operational maturity. Furthermore, the use of legitimate cloud services for C2 makes traffic analysis increasingly difficult for defenders.
Recommendations
Encrygma recommends that all organizations utilizing Zimbra collaboration suites immediately verify their patch status for CVE-2025-66376. Security teams should implement strict multi-factor authentication (MFA) for all administrative accounts and monitor for unusual API calls within their cloud environments. Additionally, organizations should review the latest forensic anchors provided in the August 14 advisory to hunt for signs of 'Ulej' or 'Flowerbed' activity within their networks.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

New Iranian Cyber Espionage Campaign Targets Global Dissidents and Journalists

NightEagle APT Escalates Cyber Espionage Campaign Against Russian Critical Infrastructure

