Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign

Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign

First seen 23 Jul 2026, 18:34 UTC Ncsc.UkInfosecurity-MagazineTechtimesDevdiscourseTheregister+15 88% similarity 80.8

Article Content

Browse articles
ThreatCluster

Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial organizations. This attack method allows hackers to steal sensitive data without requiring victims to click links or open attachments, merely by opening or previewing an email. The campaign has targeted over ten organizations, including those in the defense, energy, and technology sectors, with a focus on NATO countries and Ukraine. The vulnerability was patched in November 2025, but many systems remain unpatched. Cybersecurity agencies from the US and allied nations have issued urgent advisories to mitigate the threat. The attacks have been linked to espionage activities aimed at gathering intelligence for the Russian government.

Key Points: • Laundry Bear exploits CVE-2025-66376, a zero-click vulnerability in Zimbra. • The attack targets Western governments and organizations, including NATO members. • Urgent advisories have been issued for organizations to patch vulnerable systems.

ThreatCluster AI

Timeline

2014-06-05
CVE-2014-0224 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2015-01-09
CVE-2015-0204 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2017-03-29
CVE-2016-9924 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2017-05-17
CVE-2016-3403 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2018-01-16
CVE-2017-8802 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2018-02-04
CVE-2017-17703 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2018-03-27
CVE-2018-6882 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2018-05-30
CVE-2015-7610 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2018-05-30
CVE-2018-10939 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2018-09-05
Public exploit for CVE-2018-15131 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub

Community

Browse all →