Russian-linked campaign exploited Zimbra emails with no-click infection technique

A Russian-linked cyber-espionage group has targeted government and commercial organizations for at least a year by exploiting a vulnerability in Zimbra’s webmail platform. The campaign can compromise...

A Russian-linked cyber-espionage group has targeted government and commercial organizations for at least a year by exploiting a vulnerability in Zimbra’s webmail platform. The campaign can compromise a user when a malicious message is viewed, without requiring the recipient to click a link or open an attachment.

The activity was detailed in a joint alert issued by 27 U.S., U.K., and other international agencies. The agencies attribute the intrusions to Laundry Bear, also known as Void Blizzard, and assess that the operation is intended to obtain sensitive information for the Russian government. The group’s primary focus appears to be stealing email data.

Exploiting a Zimbra XSS flaw

The attackers abused CVE-2025-66376, a cross-site scripting vulnerability in Zimbra Collaboration Suite. Zimbra fixed the flaw in November 2025, although the campaign reportedly began exploiting it in July of that year.

Attackers sent specially crafted HTML messages containing malicious JavaScript to organizations in sectors including defense, government, education, energy, law enforcement, media, technology, and nongovernmental organizations. When rendered by the Zimbra web client, the content could trigger the attack through the act of viewing the email alone.

According to the advisory, successful compromises enabled the theft of up to 90 days of email, address books and global directories, account credentials, two-factor authentication tokens, and newly generated application passwords. The attackers then used the information to preserve access, alter mailbox settings, and gather additional authentication data.

Mitigation and investigation guidance

The stolen information was reportedly transferred to an anonymizing virtual private server using Flowerbed, a Python-based collection framework deployed with Docker. The agencies said the relatively simple code contains signs that artificial intelligence may have contributed to its development.

Organizations using Zimbra should apply the vendor’s security update and identify systems that remain exposed to CVE-2025-66376. The agencies also advised limiting employee access to the Zimbra web interface until vulnerable installations are patched. Security teams should review the alert’s indicators of compromise, investigate suspicious mailbox activity, and consider resetting credentials and authentication tokens for potentially affected accounts.