Skip to content
Russian spies exploit unpatched Zimbra flaw to steal NATO member emails

Russian spies exploit unpatched Zimbra flaw to steal NATO member emails

Cybernews • July 24, 2026

A Russian threat actor is actively exploiting an unpatched Zimbra zero-day – requiring absolutely no user clicks – to steal emails from an untold number of Western organizations in NATO member countries, according to a joint CISA advisory issued Thursday.

A nation-state threat group dubbed Laundry Bear is being blamed for the Putin-backed campaign, according to the international advisory.

The campaign is exploiting a critical vulnerability in the Zimbra Collaboration Suite (ZCS) – a business collaboration platform similar to Microsoft Exchange or Google Workspace – allowing attackers to compromise email accounts simply by sending a specially crafted email and requiring no user interaction.

Users do not have to click a link, open an attachment, or even enter their passwords to fall victim to the espionage attack – triggering alerts from cyber watchdog partner agencies across the globe, including in the UK, Canada, Australia, Italy, Spain, France, Finland, the Czech Republic, Poland, and the Netherlands.

The vulnerability, listed as Common Vulnerabilities and Exposures (CVE) CVE-2025-66376 , was patched in November 2025.

Still, the US Cybersecurity and Infrastructure Security Agency (CISA), along with the NSA, FBI, DCSA, DC3, NCIS, and the US Treasury Department, warns that many organizations have yet to patch the flaw, leaving internet-facing Zimbra servers at risk of continued exploitation.

It’s estimated that the Zimbra platform powers more than 200 million mailboxes across more than 140 countries, including an estimated 3,000 “highly regulated global institutions” in the US alone, ranging from government bodies to educational entities, CISA said.

Authorities say the hackers aim to gather sensitive intelligence for the Russian Federation, primarily focusing on the covert acquisition of email data.

The victims span multiple sectors, including government, defense, technology, and other organizations of strategic interest.

What’s more, it appears Laundry Bear first began testing its zero-click methods on organizations in Ukraine before expanding the campaign to target government and commercial organizations across NATO member countries.

Russia had been observed targeting the Zimbra productivity suite since at least July 2025. Other industry labels for the nation-state actors include Void Blizzard, CL-STA-1114, and TA488 (formerly UNK_PitStop).

The campaign – also referred to as “half-click” or “zero-click” by security researchers – requires virtually no interaction from victims, unlike traditional phishing attacks.

Simply viewing a malicious email in a vulnerable Zimbra webmail client is enough to trigger the exploit and compromise the user’s mailbox.

Once inside, the attackers deployed custom malware designed to harvest emails and maintain persistent access to compromised accounts.

The advisory provides a list of mitigation techniques and indicators of compromise (IOCs) for organizations running Zimbra.

Defenders are urged to immediately install available security updates, review systems for indicators of compromise, and investigate any suspicious activity associated with the campaign.

Based on Laundry Bear’s espionage campaigns, the advisory warns that unpatched internet-facing Zimbra servers will likely remain an attractive target for Russian intelligence operations.

“The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their effort,” CISA said.