Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
A Russian state-sponsored threat group known as Laundry Bear, also called Void Blizzard, has been exploiting a zero-day flaw in Zimbra Collaboration Suite since July 2025 to steal sensitive data from governments and commercial organizations. The campaign, which was patched only in November 2025, has targeted multiple sectors and prompted a joint advisory from the United States and more than a dozen allied countries. #LaundryBear #VoidBlizzard #ZimbraCollaborationSuite #CVE-2025-66376

Keypoints

  • Laundry Bear exploited a zero-day in Zimbra Collaboration Suite for months before it was patched.
  • The attack could steal emails, passwords, search history, directories, and two-factor authentication tokens.
  • Officials linked the campaign to Russian government-backed espionage activity.
  • The group has targeted governments and organizations across many sectors, including defense and energy.
  • Authorities released indicators of compromise and urged immediate patching of vulnerable systems.

Read More: https://cyberscoop.com/russian-laundry-bear-zimbra-exploit/