Connect with us

NEWS

Russian Hackers Still Breach Zimbra Inboxes Months After the Patch

Zimbra patched the flaw LAUNDRY BEAR exploits back in November, yet 27 agencies across 16 countries say Russian hackers are still breaching unpatched inboxes.

Published

on

Zimbra patched the flaw eight months ago. Russian state hackers are still using it to raid government email. On July 23, the National Security Agency (NSA) and 26 partner agencies across sixteen countries confirmed the exploit remains active against any server that never got the fix.

The advisory ties the campaign to LAUNDRY BEAR. Dutch intelligence first identified the Russian state-supported hacking group after tracing a breach of the Netherlands’ national police back to it. This time, the target is the Zimbra Collaboration Suite (ZCS), a webmail platform a lot of governments chose specifically so they would not have to depend on Microsoft or Google.

A Phishing Email Nobody Has to Click

The mechanism at the center of the advisory is what NSA calls a view-based exploit. It fires the moment a targeted employee opens a booby-trapped message inside a vulnerable ZCS inbox. No link, no attachment, no macro. Opening the email is enough.

The tool behind that trigger is called Ulej, Russian for “beehive.” It currently exploits CVE-2025-66376, a stored cross-site scripting flaw in ZCS’s Classic web interface, though the joint advisory notes the same capability could likely be adapted to hit other vulnerabilities down the line. Palo Alto Networks’ Unit 42 found the malicious email hides an invisible SVG graphic carrying a Base64-encoded script. Once the message loads in a vulnerable session, that script quietly injects JavaScript into the victim’s own authenticated browser tab.

From there, the joint advisory says, Ulej moves the stolen data to an actor-run server hosting LAUNDRY BEAR’s homemade Flowerbed collection framework, complete with a component the report calls Catcher, which ingests the haul, and a small script called Gardener that runs health checks on the pipeline.

Once triggered, Ulej does not stop at the message that opened the door. The joint advisory lists what it takes:

  • Email directory – the organization’s full global address list
  • 90 days of mail – the victim’s stored inbox history
  • Login credentials – the username and password tied to the session
  • Two-factor backup codes – scratch codes meant to survive a lost authenticator
  • Session tokens – active login cookies that let the actor skip past MFA entirely

Any one of those items would justify a security team’s full attention on its own. Together, they hand LAUNDRY BEAR everything it needs to keep reading a victim’s mail long after the original message gets deleted.

The Patch Existed Eight Months Before This Week’s Warning

Zimbra closed the hole in November 2025, releasing versions 10.0.18 and 10.1.13 with the fix built in, according to the company’s own security bulletin archive. At that point, CVE-2025-66376 stopped being a zero-day and became, for anyone who updated, a closed case.

A large share of ZCS deployments never got the update. In March 2026, the flaw resurfaced in a separate incident. The Indian security firm Seqrite Labs traced an intrusion at Ukraine’s State Hydrographic Service, an operation it named Operation GhostMail, back to the same bug. That finding pushed the Cybersecurity and Infrastructure Security Agency (CISA) to add CVE-2025-66376 to its Known Exploited Vulnerabilities catalog and order U.S. federal civilian agencies to patch by April 1, 2026.

Four months after that deadline came and went, NSA and 26 partner agencies confirmed the exploit still works against unpatched servers. The advisory states plainly that LAUNDRY BEAR “is still used to successfully exploit ZCS instances that are still unpatched.”

Here is what the advisory establishes, and what it leaves open:

What we know:

  • LAUNDRY BEAR has run the ZCS campaign since at least July 2025.
  • Zimbra patched the exploited flaw, CVE-2025-66376, in November 2025.
  • The exploit still succeeds against any ZCS server running an unpatched build.
  • Twenty-seven agencies across sixteen countries signed the July 23 advisory.

What remains unconfirmed:

  • How many organizations are compromised right now.
  • Whether the stolen mail has already fed follow-on operations.
  • Whether Ulej has been retooled to hit a different vulnerability.

A fix sitting in a software repository does not patch a server by itself. Someone still has to install it.

Who Is LAUNDRY BEAR?

LAUNDRY BEAR is the name Dutch intelligence gave a previously unknown, likely Russian state-backed hacking group after tracing a breach of the Netherlands’ national police force back to it. Microsoft tracks the same actor as Void Blizzard and has watched it operate globally since at least April 2024, with a heavy concentration of activity against NATO members and Ukraine’s allies.

The Netherlands General Intelligence and Security Service (AIVD) and the Netherlands Defence Intelligence and Security Service (MIVD) went public with the group’s existence in May 2025. Their joint advisory traced the intrusion to a single police employee’s account, compromised in September 2024, which the group used to pull contact records out of the force’s internal directory. Microsoft separately found the actor sending phishing emails posing as an organizer of the European Defense and Security Summit as recently as the month before its report published.

Microsoft’s own assessment of the group, published that same week, did not soften the stakes.

Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America.

Microsoft said in its May 2025 report on the group’s activity.

NSA’s new advisory frames the Zimbra campaign as a jump in capability. Earlier LAUNDRY BEAR operations leaned on cheap, high-volume methods. This one required building custom exploit code from scratch.

Capability Earlier LAUNDRY BEAR Campaigns (2024-2025) Zimbra Campaign (July 2025-Present)
Initial access Password spraying, phishing links, stolen session cookies Zero-day, zero-click exploit needing only a viewed email
Core tool Off-the-shelf credential theft Custom Ulej exfiltration framework
Confirmed target Dutch national police, September 2024 ZCS users across defense, government and commercial networks
First named publicly by AIVD and MIVD, May 2025 NSA and 26 partner agencies, July 2026

The shift matters for defenders because it changes what to watch for. Password-spray campaigns leave login logs full of failed attempts. A zero-click exploit leaves almost nothing behind until the data is already gone.

Zimbra’s Government Niche Made It a Target

Zimbra is not a household name the way Microsoft 365 or Google Workspace is, and that gap is part of why LAUNDRY BEAR picked it. The self-hosted email and calendar suite draws exactly the kind of buyer this campaign is chasing: governments, defense contractors and public institutions that would rather run their own mail servers than rent space in an American cloud.

The platform is deployed by hundreds of thousands of organizations worldwide, including government ministries, military agencies and financial institutions, according to reporting on this week’s advisory. Palo Alto Networks’ targeting assessment places the campaign’s victims in government, defense, transportation and financial sectors across NATO member states, Ukraine, other former Soviet states, and parts of Africa.

Software comparison guides routinely point to the same reason institutions pick Zimbra in the first place: its self-hosted model lets an organization keep its own data on its own servers, which is exactly what appeals to healthcare systems, school districts and ministries wary of outsourcing sensitive records to a foreign cloud provider. That same independence is what made ZCS worth building a custom zero-day for.

Sixteen Countries Signed One Warning

The roster attached to Thursday’s advisory is unusual even by the standards of prior joint cybersecurity warnings. Beyond NSA, it includes the FBI, CISA, the Department of the Treasury, the Naval Criminal Investigative Service and two other U.S. agencies, plus cyber and intelligence authorities in the Netherlands, the United Kingdom, Canada, Australia, New Zealand, Czechia, Denmark, Estonia, Finland, France, Italy, Moldova, Poland, Spain and Sweden. That is 27 agencies across 16 countries, standing behind one warning about a single webmail suite.

Several of those countries sent a domestic intelligence or counterintelligence service rather than a purely technical cyber authority. France’s DGSI, Italy’s AISI, Poland’s SKW and Moldova’s SIS RM all handle counterintelligence work at home, not routine vulnerability bulletins.

CISA’s version of the advisory spells out what to do next. Administrators should confirm their ZCS build is current, and where immediate patching is not feasible, avoid the Classic ZCS webmail client entirely until the update is applied. The report also lists specific indicators of compromise for network defenders to hunt.

Zimbra’s fix for CVE-2025-66376 has been available since November 2025, eight months before this week’s advisory told the rest of the world to go check for it.

Frequently Asked Questions

Which Zimbra Versions Fix CVE-2025-66376?

Zimbra patched the flaw in November 2025 with the release of Zimbra Collaboration Suite versions 10.0.18 and 10.1.13. Any 10.x build released before those two remains open to the exploit.

Does the LAUNDRY BEAR Campaign Affect Microsoft 365 or Google Workspace?

No. The advisory covers Zimbra Collaboration Suite specifically, and officials say Ulej was built for ZCS’s webmail interface. No activity against Microsoft 365 or Google Workspace has been reported in connection with this campaign.

How Many Zimbra Servers Are Still Exposed?

The joint advisory does not give a running count for this specific flaw. But the nonprofit Shadowserver Foundation found more than 10,500 internet-facing Zimbra servers still vulnerable to a separate cross-site scripting bug, CVE-2025-48700, when it checked in April 2026, a sign of how slowly the platform’s user base applies patches generally.

What Should an Organization Do If It Cannot Patch Immediately?

CISA recommends moving affected staff to an alternative mail client and avoiding the Classic ZCS webmail interface entirely until administrators can update to a fixed version, while also hunting for the indicators of compromise listed in the joint advisory.

Is Void Blizzard the Same Group as LAUNDRY BEAR?

Yes. LAUNDRY BEAR is the name Dutch intelligence gave the group after tracing it to the 2024 police breach. Microsoft tracks the same actor as Void Blizzard, and some researchers have also linked its activity to the designation UAC-0190.

Logan Pierce is a writer and web publisher with over seven years of experience covering consumer technology. He has published work on independent tech blogs and freelance bylines covering Android devices, privacy focused software, and budget gadgets. Logan founded Oton Technology to publish clear, no nonsense tech news and reviews based on real hands on testing. He has personally tested and reviewed dozens of mid range and budget Android phones, written extensively about app privacy, and built and managed multiple WordPress publications over the past decade. Logan holds a bachelor's degree in English and studied digital marketing at a certificate level.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending