Russian Hackers Exploit Zimbra Bug with Zero-Click Email Attack

Russian threat actors exploit Zimbra bug CVE-2025-66376 with zero-click email attacks. Learn about Laundry Bear's espionage tactics and protection tips.

viernes, 24 de julio de 2026 • 4 min read • Q2BSTUDIO Team

Campaña de espionaje Laundry Bear explota CVE-2025-66376

In the current cybersecurity landscape, zero-click attacks represent one of the most sophisticated threat vectors, as they require no user interaction beyond opening an email. Recently, an advanced persistent threat (APT) group linked to the Kremlin, known as Laundry Bear or Void Blizzard, has been actively exploiting a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS), cataloged as CVE-2025-66376. This campaign, which began in July 2025, has been detected by up to 27 government agencies from the United States, United Kingdom, and other allied nations, who attribute the attacks to this group with the goal of collecting intelligence for the Russian Federation. Unlike traditional phishing campaigns that require a click on a link or downloading a file, here it is enough for the victim to view the email in the Zimbra web client for the malicious code to execute automatically.

The CVE-2025-66376 vulnerability is a stored or reflected XSS flaw that allows an attacker to inject arbitrary JavaScript scripts into the pages rendered by the web client. In this campaign, attackers send emails with specially crafted HTML content that, when processed by Zimbra's rendering engine, executes the script without further user interaction. Once activated, the script communicates with a server controlled by the attackers and exfiltrates a wide range of data: the full email history of the last 90 days, stored session credentials, the organization's global address lists, two-factor authentication (2FA) tokens, and application passcodes generated for automated access. With these credentials, attackers can maintain persistent access to accounts, modify settings such as forwarding rules, and collect more authentication information to move laterally within the network.

Laundry Bear's modus operandi includes the use of a custom framework called 'Flowerbed', developed in Python and packaged in Docker containers. According to the joint agency report, the Flowerbed code shows signs of having been generated with artificial intelligence, suggesting that attackers are adopting AI tools to accelerate the development of their malicious infrastructure. The servers used to store stolen data are anonymous virtual private servers (VPS), difficult to trace. Email addresses identified as part of the campaign include ivanka.zurabishvili@proton.me, zmul1@buildandconsulting.com, garrysmithme@pinmx.net, and hostingclient@pinmx.net, among others. The target sectors range from the defense industry to media, governments, energy, and technology, reflecting a strategic interest in obtaining sensitive information from various fields.

From a technical perspective, zero-click attacks like this are particularly hard to detect because they do not generate click or download events that traditional intrusion prevention systems can monitor. The only effective short-term defense is to apply the patch Zimbra released in November 2025 to fix CVE-2025-66376, as well as minimize the use of the web client until the update is implemented. Organizations should also review the indicators of compromise (IOCs) published in the 31-page alert to identify potential victims. In the long term, it is crucial to adopt a multi-layered security strategy that includes network segmentation, continuous traffic monitoring, and the use of behavior-based security solutions. Incorporating artificial intelligence agents can improve anomaly detection and response automation, reducing reaction time to threats like this one.

This incident highlights the importance of having technology partners who understand both cybersecurity and software development. Q2BSTUDIO is a company specialized in cybersecurity and pentesting services, helping organizations identify vulnerabilities before they are exploited. Additionally, its development team creates custom software with security by design, integrating controls from the initial phase of the project. Experience in cloud computing, with platforms like AWS and Azure, allows migrating critical infrastructures to more secure environments, while Business Intelligence solutions with Power BI facilitate real-time security data analysis. All this, combined with the use of artificial intelligence and process automation, forms a robust defense ecosystem against advanced campaigns like Laundry Bear's.

In conclusion, the zero-click attack against Zimbra is a reminder that cybersecurity is not a static product but a continuous process requiring investment in technology, processes, and people. Companies that wish to protect themselves against advanced threats should consider outsourcing specialized services. Collaborating with experts like Q2BSTUDIO provides a competitive advantage by offering comprehensive solutions that range from secure software development to cloud infrastructure implementation and artificial intelligence integration. Not waiting to be the next victim is key; acting proactively with the right partners makes the difference between resilience and disaster.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.