How Laundry Bear exploited CVE-2025-66376 in Zimbra
For at least a year, attackers linked to the group tracked as Laundry Bear (also known as Void Blizzard) have been weaponizing a cross-site scripting vulnerability in the Zimbra Collaboration Suite (ZCS) webmail to break into government and commercial networks. The vulnerability, tracked as CVE-2025-66376, allows malicious JavaScript to be injected into web pages viewed by victims. In this campaign the attackers packaged that malicious code inside HTML email messages so the compromise begins the moment a user looks at the message — no clicking on links or opening attachments required.
Security authorities report the exploitation began in July 2025 and continued long before Zimbra released a patch in November 2025. The joint alert describes a technique that abuses the webmail rendering path itself: viewing the message runs attacker-supplied script within the context of the victim’s browser session, enabling immediate data extraction and credential theft.
Who Laundry Bear targeted and what they stole
The campaign did not spare any single sector. The joint advisory says targets included organizations in the defense industrial base, federal and local governments, education, energy, law enforcement, media, non-governmental organizations, and technology sectors. Examples of sender addresses used in the campaign include ivanka.zurabishvili@proton[.]me, zmul1@buildandconsulting[.]com, garrysmithme@pinmx[.]net, and hostingclient@pinmx[.]net.
Once the browser executed the injected script, the attackers harvested a broad swath of sensitive material. The agencies say Laundry Bear exfiltrated the victims’ last 90 days of email communications, email addresses and passwords, organizational directories such as global address lists, two-factor authentication tokens, and newly created application passcodes. Stolen credentials were then reused to maintain persistent access: the actors modified account preferences and collected further authentication information to keep channels open.
Flowerbed: the collection framework and storage
The joint alert describes how Laundry Bear consolidated stolen material on an unattributable virtual private server (VPS) running a custom collection framework called “Flowerbed.” Flowerbed is a Python project that leverages Docker for containerization. The agencies characterize the codebase as simplistic but note indications that artificial intelligence (AI) played a role in its development. The combination of easy-to-deploy containers and a VPS intended to mask origin helped the actors operationalize bulk collection and retrieval.
What the 27 US, UK, and other agencies advised and published
The advisory was issued jointly by 27 US, UK, and other international government agencies, which both attribute the intrusions to Laundry Bear and provide a 31-page security alert containing extensive indicators of compromise (IOCs). Organizations are urged to review that IOC section to identify potentially compromised accounts and individuals.
Among the concrete recommendations, the agencies advise minimizing employees’ use of the ZCS webmail client until organizations update to a patched version that is not vulnerable to CVE-2025-66376. The alert makes clear the vulnerability was patched in November 2025, but that Moscow’s attackers were exploiting the flaw long before the fix became available.
How technologists, policymakers, and affected organizations should react
- Technologists and security teams: Review the 31-page alert’s indicators of compromise to identify impacted users and accounts, and prioritize updating Zimbra instances to the patched version that remedies CVE-2025-66376. Minimize use of the ZCS webmail client where possible until patches are applied.
- Policymakers and regulators: Use the joint attribution and the advisory’s technical detail to inform guidance on email platform risk, cultural expectations for timely patching, and disclosure timelines for intrusions that involve credential and directory exfiltration.
- Affected enterprises and procurement leaders: Reassess exposure where Zimbra webmail is in use, verify whether email directories and account settings were modified, and account for possible persistence through stolen two-factor tokens and application passcodes when planning remediation.
The advisory paints a tidy, disquieting portrait: a Kremlin-linked actor exploited a known webmail flaw to turn innocent message previews into a wholesale data siphon, collecting three months’ worth of correspondence and the credentials to keep coming back. The presence of a containerized, Python-based collection tool and an unattributable VPS suggests the campaign was engineered to scale and to obscure origins. Organizations that relied on ZCS webmail faced a choice the agencies now make explicit — minimize use and patch aggressively — and the 31-page alert provides the technical leads to do it.




