Tag: laundry bear
7 articles

Russian Spies Expand Email Attacks to Outlook
Russian spies have set their sights on Microsoft Outlook Web Access, exploiting a cross-site scripting flaw to launch targeted email attacks, just days after being called out for their abuse of a zero-day vulnerability in Zimbra Collaboration Suite. The notorious group, tracked as TA488 or Laundry Bear, has adapted their sneaky half-click technique to compromise on-premises Exchange Servers.

Russian Hackers Exploit Microsoft OWA Flaw to Maintain Mailbox Access
Russian hackers have found a sneaky way to keep access to Microsoft mailboxes by exploiting a flaw in Outlook Web Access, making it tough to shake them off even with a full system overhaul. Simply put, these cyber intruders can stick around unless their presence is manually erased from the Exchange server.

Russian Hackers Exploit Exchange Zero-Day for Long-Term Mailbox Access
Russian hackers have unleashed a powerful tool, dubbed OWAReaper, exploiting a zero-day flaw in Exchange Outlook Web Access to gain long-term access to mailboxes, with Proofpoint hailing it as the most sophisticated backdoor delivered via half-click exploits they've ever seen. The attack, linked to the Russian state-sponsored group Laundry Bear, cleverly uses a cross-site scripting flaw to execute arbitrary JavaScript in victims' browsers.

Kremlin Hackers Exploit Zimbra Bug to Infiltrate Networks
Kremlin hackers, also known as Laundry Bear, have been exploiting a vulnerability in the Zimbra Collaboration Suite to secretly infiltrate government and commercial networks for over a year, aiming to gather sensitive information for the Russian Federation. They've been using malicious emails to inject JavaScript code, allowing them to covertly acquire email data.

Russian Hackers Exploit Zimbra Flaw for Widespread Email Theft
Russian hackers have exploited a Zimbra flaw, CVE-2025-66376, to steal emails from targeted organizations, allowing them to automatically collect a victim's last 90 days of email without requiring any interaction. This alarming vulnerability was weaponized by the Russian state-sponsored group Laundry Bear using a combination of phishing and specially crafted HTML emails.

Russian Hackers Exploit Zero-Click Attack on Western Organizations
Russian hackers have launched a stealthy zero-click attack, dubbed "beehive," targeting Western organizations by exploiting a vulnerability in the Zimbra Collaboration Suite, allowing them to siphon off sensitive emails and data with just a viewed email. This alarming threat highlights the need for organizations to bolster their defenses against such sophisticated cyber threats.

Russian national charged in Void Blizzard cyber-espionage scheme
A Russian national, Denis Nikolayevich Obrezko, has been charged with helping facilitate a massive cyber-espionage scheme that infiltrated at least 11 US companies, with authorities suspecting many more victims nationwide. Obrezko allegedly played a key role in the Void Blizzard campaign by buying a virtual private server and registering domain names used in the intrusions.