Proofpoint
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Article Content
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial organizations. This attack method allows hackers to steal sensitive data without requiring victims to click links or open attachments, merely by opening or previewing an email. The campaign has targeted over ten organizations, including those in the defense, energy, and technology sectors, with a focus on NATO countries and Ukraine. The vulnerability was patched in November 2025, but many systems remain unpatched. Cybersecurity agencies from the US and allied nations have issued urgent advisories to mitigate the threat. The attacks have been linked to espionage activities aimed at gathering intelligence for the Russian government.
Key Points: • Laundry Bear exploits CVE-2025-66376, a zero-click vulnerability in Zimbra. • The attack targets Western governments and organizations, including NATO members. • Urgent advisories have been issued for organizations to patch vulnerable systems.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.