Infosecurity-Magazine
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial organizations. This attack method allows hackers to steal sensitive data without requiring victims to click links or open attachments, merely by opening or previewing an email. The campaign has targeted over ten organizations, including those in the defense, energy, and technology sectors, with a focus on NATO countries and Ukraine. The vulnerability was patched in November 2025, but many systems remain unpatched. Cybersecurity agencies from the US and allied nations have issued urgent advisories to mitigate the threat. The attacks have been linked to espionage activities aimed at gathering intelligence for the Russian government.
Key Points: • Laundry Bear exploits CVE-2025-66376, a zero-click vulnerability in Zimbra. • The attack targets Western governments and organizations, including NATO members. • Urgent advisories have been issued for organizations to patch vulnerable systems.