Russian Hackers Exploited Zimbra Zero-Day to Target US and Ukrainian Organizations
Want more insights like this?
A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day that only required victims to open or preview an email — no clicking required.
The haul was substantial: victims' last 90 days of email, addresses and passwords, the organization's email directory including its Global Address List, two-factor authentication tokens, and newly created application passcodes.
Zimbra patched the flaw in version 10.1.13 in November 2025, but the campaign ran undetected for months, and CISA only added it to its Known Exploited Vulnerabilities catalog in March 2026. Proofpoint, which tracks the group as TA488, has seen no activity since February — after researchers at Seqrite went public and the group tore down its own infrastructure.
Organizations still running unpatched Zimbra remain at risk. Update, review authentication logs, and revoke any unauthorized application passcodes — especially ones named "ZimbraWeb."
Source: Dark Reading