<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Russian Hackers Exploited Zimbra Zero-Day to Target US and Ukrainian Organizations

Russian hackers Laundry Bear exploited a Zimbra flaw to breach US and Ukrainian servers, stealing email and 2FA tokens. Unpatched systems remain at risk.
Content Team

A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day that only required victims to open or preview an email — no clicking required.

The haul was substantial: victims' last 90 days of email, addresses and passwords, the organization's email directory including its Global Address List, two-factor authentication tokens, and newly created application passcodes.

Zimbra patched the flaw in version 10.1.13 in November 2025, but the campaign ran undetected for months, and CISA only added it to its Known Exploited Vulnerabilities catalog in March 2026. Proofpoint, which tracks the group as TA488, has seen no activity since February — after researchers at Seqrite went public and the group tore down its own infrastructure.

Organizations still running unpatched Zimbra remain at risk. Update, review authentication logs, and revoke any unauthorized application passcodes — especially ones named "ZimbraWeb."

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo