A coalition of cybersecurity and intelligence agencies from the United States, Netherlands, United Kingdom, Australia, Canada, New Zealand and multiple European partners has issued a joint advisory warning that a Russian state-supported threat group has been actively compromising organizations running Zimbra Collaboration Suite (ZCS) since at least July 2025.

The group, tracked in the security community under several names but primarily as “LAUNDRY BEAR” (a designation first assigned by the Netherlands’ AIVD and MIVD), has historically relied on low-sophistication techniques such as password spraying, credential phishing, and pass-the-cookie session hijacking to run high-volume espionage operations. The advisory states this campaign marks a notable escalation in capability.

A view-only exploit

Unlike conventional phishing that requires a victim to click a link or open an attachment, this campaign leverages CVE-2025-66376, a vulnerability in ZCS that was a zero-day at the time of initial exploitation. The flaw allows an attacker-controlled email to compromise a victim’s account the moment it is simply viewed in a vulnerable version of the webmail client, no further interaction required.

Once triggered, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization’s Global Address List (GAL), and other sensitive data to infrastructure controlled by the attackers. The malicious code also attempts to establish persistent access to compromised accounts through multiple mechanisms detailed in the advisory’s technical sections.

Agencies assess LAUNDRY BEAR’s targeting is aimed at gathering sensitive information on behalf of the Russian government, with a primary focus on covertly acquiring email content from Western government and commercial organizations.

Patched, but exploitation continues

CVE-2025-66376 was patched in November 2025, yet the advisory notes the vulnerability continues to be successfully exploited in the wild, indicating many organizations have not yet applied the update. Agencies expect exploitation to decline as more organizations patch their ZCS deployments.

Recommendations

  • Update Zimbra Collaboration Suite to a patched version immediately.
  • Review the advisory’s indicators of compromise (IOCs) and follow the specified remediation steps if any are found in your environment.
  • Audit accounts for signs of persistence mechanisms and unauthorized session activity.
  • Monitor for anomalous outbound traffic consistent with mass email or directory exfiltration.

The advisory was co-sealed by more than a dozen additional national intelligence and cybersecurity agencies, reflecting the breadth of organizations affected across allied nations.