Russian state-backed actors target Zimbra email users with phishing campaign
Russian state-supported cyber actors from the group LAUNDRY BEAR are conducting a phishing campaign targeting Zimbra Collaboration Suite users. The attackers exploit vulnerability CVE-2025-66376, which allows email exfiltration and account access without requiring user interaction beyond viewing a malicious message in the web client. A consortium of security agencies, including U.S. NSA, FBI, and CISA, as well as Czech NÚKIB, issued the warning.
Email is a highly valuable source of information, enabling attackers to obtain not only compromising materials but also access credentials to other services.
What is LAUNDRY BEAR?
LAUNDRY BEAR is a Russian state-supported cyber actor group focused on stealing sensitive information, particularly emails, from Western government and commercial organizations. The group is also known in the security community as Void Blizzard and other designations. It has been active since at least April 2024.
How does the CVE-2025-66376 exploit work?
The vulnerability enables attacks without user interaction—viewing a malicious email in the Zimbra web client is sufficient for the exploit to execute. It automatically exfiltrates the last 90 days of email communications, the organization's email directory, and attempts to establish persistent access to the victim's account.
Which organizations are at risk?
Target organizations are Western government and commercial entities using Zimbra Collaboration Suite. Historically, the group has also targeted Microsoft Exchange users and other email system users.
- New malware can extract passkeys from Google Password Manager — bleepingcomputer.com 74 % match
- Kimsuky builds offline AI stack to enhance phishing and automate malware development — thehackernews.com 72 % match
- Android 17 implements ECH to hide website visits from network providers — thehackernews.com 72 % match
- LAUNDRY BEAR
- Zimbra Collaboration Suite
- CVE-2025-66376
- Void Blizzard
- NÚKIB
- NSA
- FBI
- CISA
- Microsoft Exchange
- Evilginx