Close Menu
NCIJ Network |NCIJ Network |
    What's Hot

    OpenAI is making big claims as it rolls out ChatGPT Health to everyone

    July 24, 2026

    How to Build an End-to-End OCR Pipeline with Baidu’s Unlimited-OCR for High-Resolution Images and Multi-Page PDF Parsing

    July 24, 2026

    Hackers abuse Notepad++ plugins to stealthily install malware

    July 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • OpenAI is making big claims as it rolls out ChatGPT Health to everyone
    • How to Build an End-to-End OCR Pipeline with Baidu’s Unlimited-OCR for High-Resolution Images and Multi-Page PDF Parsing
    • Hackers abuse Notepad++ plugins to stealthily install malware
    • Nasdaq-Listed Zhibao Wants a Bitcoin Treasury, Plans to Sell $220M in Stock for BTC
    • How Israeli Arms Makers Are Adapting to Global Backlash
    • Image shows smoke rising from Russian warehouse after Ukrainian drone strike
    • Ukraine beheads its military as its performance begins to soar | Russia-Ukraine war News
    • Urgent need for more security after physical attacks and abuse, say MPs’ staff | Politics
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network |NCIJ Network |
    Friday, July 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network |NCIJ Network |
    Home»Cybersecurity

    Russian hackers exploit Zimbra zero-click flaw for email theft

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 24, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability.

    According to CISA, Laundry Bear has targeted and compromised users in organizations associated with the Defense Industrial Base (DIB), federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology.

    The attackers exploit the Zimbra CVE-2025-66376 flaw, a cross-site scripting (XSS) vulnerability affecting Zimbra Collaboration Suite’s Classic UI.

    image

    The flaw allows JavaScript embedded in specially crafted HTML emails to execute automatically when a victim views the message, enabling attackers to steal account data without requiring the user to click a link or visit a phishing site.

    According to CISA, Laundry Bear exploited the flaw as a zero-day before Zimbra patched it in November 2025 and continues to target organizations running unpatched servers. The vulnerability was later tagged by CISA as actively exploited in attacks.

    CISA says Laundry Bear’s exploit is used to automatically collect and send the victim’s last 90 days of emails, email address, password, Global Address List (GAL), and two-factor authentication (2FA) tokens.

    The attackers also create and send back a new Zimbra application passcode, which is used by legacy email clients like IMAP or ActiveSync that do not support the TOTP authentication flows. Using a passcode allows the attackers to retain access to the email account while bypassing MFA.

    According to CISA, the malware exfiltrates stolen information over both DNS and HTTPS to an actor-controlled server running the group’s “Flowerbed” collection framework.

    Smaller data is encoded and transmitted in DNS A-record queries, while larger payloads, including mailbox data, are uploaded over HTTPS as compressed archives to the attacker-controlled servers.

    In addition to exploiting the Zimbra flaw, Laundry Bear also utilizes adversary-in-the-middle (AiTM) phishing kits designed to impersonate legitimate Zimbra login portals, stealing credentials and session cookies, allowing the attackers to gain access to targets’ email accounts.

    CISA released IOCs that show the campaign used sites that impersonate Zimbra infrastructure, using domain names like ‘mailnalysis.com’, ’emailanalytics.com.ua’, ‘zimbrastat.com’, ‘zimbra-metadata.com’, ‘istc-cloud.com’, and ‘zmailanalytics.com’.

    The advisory recommends that organizations using Zimbra:

    • Update to the latest version of the software to install all available security updates.
    • Review the published indicators of compromise.
    • Investigate systems for connections to the identified domains and IP addresses.
    • Monitor for suspicious authentication activity.
    • Revoke any unauthorized application passcodes, especially those with the ‘ZimbraWeb’.
    • Review accounts for unauthorized mailbox access.

    CISA also recommends implementing phishing-resistant multi-factor authentication where possible.

    Laundry Bear targeted governments, police, and Ukraine

    The Laundry Bear hacking group was first attributed to cyberespionage attacks in May 2025 by the Dutch intelligence agencies.

    The Dutch agencies publicly attributed the group to a 2024 compromise of the Dutch National Police that exposed the personal information of police personnel and led to the identification of a previously unknown Russian espionage group.

    Microsoft tracks the same group under the name Void Blizzard.

    Since at least 2024, the group has focused on intelligence collection against organizations aligned with Russian strategic interests, primarily targeting NATO member states and Ukraine.

    Microsoft has also documented successful compromises of organizations supporting Ukraine, including entities in the defense, transportation, and aviation sectors.

    Earlier this year, BleepingComputer reported on a separate Laundry Bear campaign targeting Ukraine’s military using charity-themed phishing emails to deliver malware disguised as donation requests.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    email exploit Flaw hackers Russian theft zeroclick Zimbra
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers abuse Notepad++ plugins to stealthily install malware

    Image shows smoke rising from Russian warehouse after Ukrainian drone strike

    Chick-fil-A Accounts Get Fried in Credential Stuffing Attack

    Australian energy provider Origin says data breach exposes client data

    New Dolphin X malware uses AI to rank high-value targets

    Is Patching Dead? Vulnerability Management in the Post-Mythos Era

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    OpenAI is making big claims as it rolls out ChatGPT Health to everyone

    July 24, 2026

    How to Build an End-to-End OCR Pipeline with Baidu’s Unlimited-OCR for High-Resolution Images and Multi-Page PDF Parsing

    July 24, 2026

    Hackers abuse Notepad++ plugins to stealthily install malware

    July 24, 2026

    Nasdaq-Listed Zhibao Wants a Bitcoin Treasury, Plans to Sell $220M in Stock for BTC

    July 24, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    OpenAI is making big claims as it rolls out ChatGPT Health to everyone

    July 24, 2026

    How to Build an End-to-End OCR Pipeline with Baidu’s Unlimited-OCR for High-Resolution Images and Multi-Page PDF Parsing

    July 24, 2026

    Hackers abuse Notepad++ plugins to stealthily install malware

    July 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.