Skip to main content
Emerging ThreatsMalware & Ransomware

Russian Hackers Exploit Zimbra Flaw for Widespread Email Theft

Government officials gather in a secure briefing room with a computer screen visible in the background.

CVE-2025-66376 allowed attackers to automatically collect a victim's last 90 days of email without any click or link, CISA warns.

How the vulnerability was weaponized

According to the Cybersecurity and Infrastructure Security Agency (CISA), the Russian state-sponsored group Laundry Bear — also tracked by Microsoft as Void Blizzard — combined phishing and a now-patched Zimbra vulnerability to steal email data from targeted organizations. The flaw, CVE-2025-66376, is a cross-site scripting (XSS) issue in Zimbra Collaboration Suite's Classic UI that permits JavaScript embedded in specially crafted HTML emails to execute automatically when a victim opens the message. Because the code runs on view, CISA says attackers did not need victims to click links or visit separate phishing sites to start harvesting account data.

What the attackers took and how they kept access

CISA reports Laundry Bear's exploit automatically collected and sent the victim's last 90 days of emails, email address, password, Global Address List entries, and two-factor authentication (2FA) tokens. The group also created and returned a new Zimbra application passcode — notably ones labeled with 'ZimbraWeb' — to be used by legacy clients such as IMAP or ActiveSync that do not support modern TOTP flows, allowing attackers to retain access while bypassing multi-factor protections.

Exfiltration techniques and infrastructure

The advisory details a two-channel data exfiltration method. Smaller items were encoded and transmitted in DNS A-record queries, while larger payloads — including mailbox archives covering the 90-day window — were uploaded over HTTPS as compressed archives to actor-controlled servers. CISA attributes the group's collection framework as "Flowerbed." In parallel to exploiting CVE-2025-66376, Laundry Bear used adversary-in-the-middle (AiTM) phishing kits impersonating legitimate Zimbra login portals to steal credentials and session cookies.

Targets, attribution, and prior activity

CISA says Laundry Bear has targeted organizations associated with the Defense Industrial Base (DIB), federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology. The Dutch intelligence agencies first attributed the group to cyberespionage in May 2025, linking it to a 2024 compromise of the Dutch National Police. Microsoft tracks the same actor as Void Blizzard and has documented compromises against organizations supporting Ukraine, including entities in defense, transportation, and aviation. BleepingComputer previously reported an earlier Laundry Bear campaign that targeted Ukraine's military with charity-themed phishing emails delivering malware disguised as donation requests.

CISA indicators, active exploitation, and recommended actions

CISA says Laundry Bear exploited the Zimbra flaw as a zero-day prior to Zimbra issuing a patch in November 2025, and that the vulnerability was later tagged by CISA as actively exploited. The agency published indicators of compromise (IOCs) showing campaign infrastructure that impersonated Zimbra services using domain names such as 'mailnalysis.com', 'emailanalytics.com.ua', 'zimbrastat.com', 'zimbra-metadata.com', 'istc-cloud.com', and 'zmailanalytics.com'.

  • CISA's advisory recommends updating Zimbra to the latest version and installing all security updates.
  • Organizations are urged to review published IOCs and investigate systems for connections to the identified domains and IP addresses.
  • Monitor for suspicious authentication activity and review accounts for unauthorized mailbox access.
  • Revoke any unauthorized application passcodes — especially those with the 'ZimbraWeb' label — and implement phishing-resistant multi-factor authentication where possible.

What this means for security teams, governments (including the DIB), and Zimbra users

Security teams should prioritize patching Zimbra servers and hunting for the IOCs CISA published, because CISA says attackers continue to target unpatched installations and used both zero-click XSS and AiTM phishing in the same campaign. Governments and organizations in the Defense Industrial Base must treat mailbox access as a high-value breach vector: CISA's description of exfiltrated GAL entries, credentials, and 2FA material means lateral intelligence collection and impersonation risks increase if accounts are not promptly remediated. Zimbra end users and administrators should revoke suspicious application passcodes, audit recent mailbox activity for unauthorized access, and shift toward phishing-resistant MFA to reduce the risk posed by legacy passcode mechanisms.

For defenders the takeaway is practical and immediate: a disclosed XSS in an email platform became a zero-click remote mailbox-collection capability in active operations, and the attackers paired it with phishing and custom collection tooling to sustain access. CISA's combination of IOCs and clear remediation steps creates a narrow operational window — patch, hunt, revoke, and monitor — for organizations that still run unpatched Zimbra servers.

Read the original CISA-linked advisory and reporting here: https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/