Skip to content
Zero

Zero

Techtimes July 23, 2026

A Russian state-linked hacking group has been quietly raiding email accounts at NATO government agencies, defense contractors, and critical infrastructure operators since mid-2025 using a zero-click vulnerability in one of the world's most widely deployed enterprise webmail platforms — and security researchers publishing simultaneous reports Thursday say the attacks have not stopped.

Palo Alto Networks' Unit 42 and the US Cybersecurity and Infrastructure Security Agency (CISA) both issued advisories today documenting the campaign, which Unit 42 tracks as CL-STA-1114 in Unit 42's CL-STA-1114 report . The group behind it is known to the broader security community as Void Blizzard — or LAUNDRY BEAR , the designation assigned by Dutch intelligence services who first identified the actor after it breached the Netherlands' national police force in September 2024, as documented in the AIVD and MIVD joint advisory . The two names refer to the same organization. Microsoft Threat Intelligence's May 2025 assessment places the group as Russia-affiliated and operating in support of Russian strategic intelligence objectives with high confidence.

A US federal criminal case opened in June 2026 named Denis Obrezko, a 36-year-old Russian citizen and former FSB employee, as a participant in the campaign. He is currently awaiting trial in Boston after his arrest in Phuket, Thailand in November 2025, as reported in Denis Obrezko's court appearance coverage. Obrezko has pleaded not guilty.

The technical core of this campaign is a stored cross-site scripting vulnerability in Zimbra Collaboration Suite's Classic UI, tracked as CVE-2025-66376 , per Unit 42's technical analysis . Zimbra is deployed by hundreds of thousands of organizations globally, including government ministries, military agencies, and financial institutions.

The attack begins with a phishing email built around news headlines — content designed to look credible enough to open. The email's HTML body contains an invisible Scalable Vector Graphics (SVG) element carrying a Base64-encoded script. When the email loads inside a vulnerable Zimbra webmail session, the SVG element silently decodes and injects a malicious JavaScript payload directly into the victim's browser, as described in Unit 42's technical analysis of the attack chain . No link click is required. No attachment needs to be opened. The attack completes the moment the email renders.

This is the defining characteristic of a zero-click exploit: the attack surface is not the user's judgment but the software's automatic data-processing behavior. Security awareness training — "don't click suspicious links," "don't open unexpected attachments" — offers zero protection, because the victim does nothing. An organization that relies on trained employees as its primary email defense has no defense here. Patching is the only mitigation, as CISA's advisory AA26-204A makes clear.

The vulnerability was designated CVE-2025-66376 with a CVSS score of 7.2. Zimbra patched it in November 2025 with the release of ZCS versions 10.0.18 and 10.1.13, documented in Zimbra's November 2025 security release . When Void Blizzard first began deploying this exploit in July 2025, the vulnerability was an unpatched zero-day — meaning organizations had no vendor-supplied fix available for approximately four months while the campaign ran, a period CISA's advisory confirming the zero-day period describes as demonstrating the group's growing technical sophistication.

Once the injected JavaScript executes inside the victim's authenticated webmail session, it systematically harvests and transmits a broad package of credential and communications data to a hard-coded command-and-control server, according to Unit 42's data exfiltration findings . The exfiltrated data includes: CSRF tokens, the victim's email address and password, two-factor authentication scratch codes, system and environment fingerprints, and the victim's last 90 days of email and history.

The theft of 2FA scratch codes warrants specific attention. These backup codes — typically given to users as emergency bypasses when their authenticator app is unavailable — are designed to work in place of the regular second factor. An attacker holding valid scratch codes can authenticate to a Zimbra account even after the account's primary password has been reset.

This distinction matters for how organizations respond to discovery of a compromise. Resetting account passwords is standard incident response procedure. But an organization that resets passwords without also revoking and regenerating 2FA scratch codes and invalidating all active sessions has not expelled the attacker. The campaign's credential theft is designed not just to yield a snapshot of access but to establish a durable foothold that survives the most obvious response, as detailed in Unit 42's analysis of 2FA code theft .

The theft of 90 days of email history compounds the long-term damage. An attacker who has read three months of an organization's internal communications has read sourcing conversations, budget discussions, and operational coordination — intelligence value that persists long after the initial intrusion is contained.

Unit 42's targeting assessment identifies the targeting scope as governments, defense organizations, transportation companies, and financial institutions across NATO member states, Ukraine, Commonwealth of Independent States (CIS) countries, and Africa, with campaign activity running since at least July 2025.

Microsoft's Void Blizzard profile , which has tracked Void Blizzard since at least April 2024, describes the group's operations as specifically oriented toward organizations of Russian government interest — including government agencies, defense contractors, transportation, media, NGOs, and healthcare, primarily in Europe and North America. The targeting disproportionately concentrates on NATO member states and countries providing military or humanitarian support to Ukraine.

The Dutch intelligence services (AIVD and MIVD) — who named the group LAUNDRY BEAR after tracing an intrusion at the Netherlands' national police in September 2024 — offered the clearest statement of collection intent. MIVD Director Vice Admiral Peter Reesink stated in the Dutch intelligence advisory on LAUNDRY BEAR that the group is targeting information the purchase and production of military equipment by Western governments, and weapons deliveries to Ukraine from Western countries. In other words: the campaign's collection priorities track directly against NATO operational security around Ukraine.

The campaign's backend architecture reflects a deliberate strategy of operational persistence. Unit 42's infrastructure analysis documents at least nine IP addresses and nine domains used for C2 servers over the course of the campaign, with those servers remaining active for an average of 35.4 days before rotation. Regular cycling of infrastructure limits the effectiveness of IP blocklists and makes it harder for defenders to build a complete picture of the operation.

The documented C2 domains use naming conventions designed to blend with legitimate Zimbra-related traffic, including zimbrastat[.]com , zmailanalytics[.]com , and analyticemailmeter[.]com . Organizations that discover these domains in historical traffic logs should treat the match as a strong indicator of compromise.

Despite cycling through infrastructure, Unit 42 observed minimal changes to the JavaScript payload itself throughout the campaign. Attackers found a working exploitation formula in July 2025 and saw no need to retool. Operational stability in the exploit code combined with rapid infrastructure turnover is characteristic of a well-resourced and disciplined threat actor.

The attribution to Russian state interests rests on convergent findings from multiple independent sources. Unit 42's CL-STA-1114 cluster overlaps with Void Blizzard activity documented by Microsoft's cross-actor analysis in May 2025 and the LAUNDRY BEAR actor identified and attributed to Russia by Dutch intelligence services AIVD and MIVD in May 2025.

Microsoft further notes that organizations compromised by Void Blizzard frequently overlap with past or concurrent targeting by other Russian state actors — Forest Blizzard, Midnight Blizzard, and Secret Blizzard — suggesting shared intelligence collection tasking assigned at an organizational level above any single group, according to the Microsoft cross-actor analysis .

The FBI affidavit filed in the Obrezko case identifies at least 11 US companies that have been compromised — a figure the filing describes as believed to be a fraction of total victims. The case attributes Void Blizzard's technical infrastructure to Yutek-NN, a Russian company where Obrezko served as deputy director, holding an FSB-issued license for surveillance-related technology, per Ctrl-Alt-Intel's analysis of the Yutek-NN connection .

CISA's remediation guidance and Unit 42's report both identify priority patching as the most urgent action for any organization running Zimbra Collaboration Suite. Organizations should verify their ZCS installations are running versions 10.0.18, 10.1.13, or later. Any instance running an older version should be treated as potentially compromised for any period after July 2025.

CISA also notes that organizations unable to patch immediately should advise employees to use alternative mail clients to access their email rather than the Zimbra Classic UI webmail interface.

Security teams should also conduct three additional remediation steps for any accounts that may have accessed Zimbra webmail on unpatched systems during the campaign window:

First, revoke and regenerate 2FA scratch codes — not just reset passwords. As described above, the malware specifically exfiltrates these codes to provide persistent access that survives password resets alone.

Second, review historical network traffic against the nine C2 IP addresses and nine domains published in Unit 42's IoC list. Any match in historical logs should be treated as a probable indicator of data exfiltration, not merely a connection attempt.

Third, assume email contents for the 90-day window before discovery may be in adversary hands. For affected accounts in government or defense sectors, this may require reassessing source protection, operational security for active programs, and communications that were treated as internal-only.

Unit 42 has shared its findings with Cyber Threat Alliance members to enable rapid deployment of protections by partner organizations. The full indicators of compromise — all nine C2 IP addresses and all nine associated domains — are published in Unit 42's CL-STA-1114 report .

Because this attack requires no click. The Zimbra zero-click exploit fires the moment an email renders in a vulnerable webmail session — before any action by the user. Standard security guidance ("don't click suspicious links," "don't open unexpected attachments") does not apply, because the attack completes during automatic email processing. The only protection is patching ZCS to version 10.0.18 or 10.1.13 or later, or avoiding the Zimbra Classic UI webmail client until a patch can be applied, as explained in Unit 42's zero-click mechanism analysis .

No. The Void Blizzard malware specifically exfiltrates 2FA scratch codes — the emergency backup codes that bypass your authenticator app. An attacker who holds those codes can authenticate to your accounts even after a password reset. Full remediation requires revoking and regenerating all 2FA scratch codes for affected accounts, invalidating existing active sessions, and treating the 90-day email history of affected accounts as potentially read by the attacker. Incident response teams should treat this as a persistent-access intrusion rather than a standard credential compromise, per Unit 42's remediation guidance on 2FA codes .

All ZCS 10.x versions prior to 10.0.18 and 10.1.13 are vulnerable to CVE-2025-66376. These versions were released November 6, 2025. Administrators can check their installed version in the Zimbra admin console. CISA's advisory and patch deadline ordered US federal agencies to patch by April 1, 2026 under Binding Operational Directive 22-01; non-federal organizations should treat this as a critical priority regardless of that deadline.

Yes, for two reasons. First, any unpatched ZCS instance is vulnerable to exploitation by any threat actor, not just Void Blizzard. CVE-2025-66376 is now publicly documented and in CISA's Known Exploited Vulnerabilities catalog, meaning other attackers with less sophisticated objectives than Russian military intelligence may also be weaponizing it. Second, CISA's advisory on targeting scope notes that Void Blizzard's targeting is broad — governments, defense, transportation, finance, NGOs, and healthcare across NATO member states, Ukraine, CIS countries, and Africa. If your organization operates in any of those sectors or geographies, you are within the campaign's targeting scope.