Russian state-supported actors tracked as LAUNDRY BEAR have been exploiting CVE-2025-66376 in Zimbra Collaboration Suite to steal email data and sensitive account information from Western organizations. The campaign uses a view-based phishing exploit, custom tooling called Ulej, and Flowerbed/Catcher infrastructure to collect and exfiltrate data via DNS and HTTPS. #LAUNDRYBEAR #ZimbraCollaborationSuite #CVE202566376 #Ulej #Flowerbed #Catcher
Keypoints
- LAUNDRY BEAR, a Russian state-supported APT, has targeted Western government and commercial organizations since at least July 2025.
- The group exploited CVE-2025-66376 in Zimbra Collaboration Suite using a malicious email that executes JavaScript when merely viewed.
- The campaign focused on stealing the last 90 days of email content, Global Address List data, passwords, 2FA scratch codes, and application passcodes.
- LAUNDRY BEAR used custom tooling named Ulej and infrastructure tied to Flowerbed and Catcher to aggregate and move stolen data.
- Exfiltration occurred through both DNS and HTTPS, with payloads encoded, encrypted, and staged to evade basic detection.
- Indicators of compromise include suspicious domains, VPS infrastructure, malicious email hashes, and artifacts such as ZCS localStorage entries and SOAP request activity.
- Mitigations include patching ZCS, using alternative mail clients if needed, monitoring SOAP and DNS activity, and revoking exposed passcodes and credentials.
MITRE Techniques
- [T1114.002] Remote Email Collection â The group abused legitimate APIs to bulk exfiltrate cloud email data (âabusing legitimate APIs to perform data exfiltration in bulkâ).
- [T1078] Valid Accounts â The actors used stolen credentials from criminal marketplaces and compromised accounts to access victim mail (âprocuring stolen credentials on criminal marketplacesâ).
- [T1557] Adversary-in-the-Middle â Evilginx intercepted credentials and session tokens from a fake sign-in site (âintercepted the userâs credentialsâ).
- [T1587.001] Develop Capabilities: Malware â LAUNDRY BEAR used a custom-developed capability named Ulej (âa custom-developed capability named âУНоКâ or âUlejââ).
- [T1114] Email Collection â The campaign targeted ZCS to steal email communications (âsuccessfully targeted and exfiltrated sensitive user informationâ).
- [T1589.001] Gather Victim Identity Information: Credentials â The script attempted to collect the victimâs password (âPasswordâ).
- [T1087] Account Discovery â The payload searched for the victimâs email address and gathered the GAL (âattempts to discover the victimâs email addressâ).
- [T1098] Account Manipulation â The script created a new application passcode to support persistent access (âNewly-created Application Passcodeâ).
- [T1595] Active Scanning â LAUNDRY BEAR likely found Zimbra targets via port scanning (âby port scanningâ).
- [T1596.005] Search Open Technical Databases: Scan Databases â The group used commercial fingerprinting datasets to identify targets (âfingerprinting datasets easily procuredâ).
- [T1597.002] Search Closed Sources: Purchase Technical Data â The actors compiled user email addresses from commercial datasets (âdatasets offered by commercial vendorsâ).
- [T1593] Search Open Websites/Domains â Open source intelligence helped build target lists (âopen source intelligenceâ).
- [T1583.003] Acquire Infrastructure: Virtual Private Server â The actors procured VPSs for staging and exfiltration (âprocure VPSs from a variety of providersâ).
- [T1583] Acquire Infrastructure â Mullvad VPN was used to mask infrastructure interactions (âprimarily uses Mullvad VPNâ).
- [T1608] Stage Capabilities â Docker containers for Flowerbed were deployed onto new servers (âdeploy the Docker containers necessaryâ).
- [T1048] Exfiltration Over Alternative Protocol â Catcher received victim data over DNS and HTTP (âacts as both a DNS and HTTP serverâ).
- [T1048.002] Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol â HTTPS was used as an encrypted exfiltration channel (âdisguise some of its exfiltration activity through an encrypted communications channelâ).
- [T1588.007] Obtain Capabilities: Artificial Intelligence â The Flowerbed codebase shows signs AI helped with development (âartificial intelligence (AI) played a roleâ).
- [T1588.002] Obtain Capabilities: Tool â The group relied on Evilginx2 as an open source tool (âopen source capabilities, such as Evilginx2â).
- [T1566] Phishing â The initial access vector was a malicious email payload (âsends an email containing a malicious JavaScript payloadâ).
- [T1203] Exploitation for Client Execution â Viewing the malicious email executed JavaScript in the client (âimmediately executed once the user viewsâ).
- [T1587.004] Develop Capabilities: Exploits â The campaign used a zero-day exploit at the time (âinitially exploited a zero-day vulnerabilityâ).
- [T1027.017] Obfuscated Files or Information: SVG Smuggling â The payload was hidden in an SVG onload attribute (âwithin the âonloadâ field of a Scalable Vector Graphics elementâ).
- [T1027.013] Obfuscated Files or Information: Encrypted/Encoded File â The inner payload was Base64-encoded and XOR-encrypted (âBase64 inner payloadâ).
- [T1027.010] Obfuscated Files or Information: Command Obfuscation â The payload used extra non-functional @import directives to bypass detection (âadding additional @import directives with non-functional codeâ).
- [T1119] Automated Collection â The payload collected and exfiltrated information in stages (â12 asynchronous stagesâ).
- [T1550.004] Use Alternate Authentication Material: Web Session Cookie â Prior campaigns bypassed MFA using session token replay (âcircumvent multi-factor authentication through session token replayâ).
- [T1185] Computer Account Discovery â The script used SOAP to determine the victimâs email address (âGetIdentitiesRequest ⌠to determine the victimâs email addressâ).
- [T1556.006] Modify Authentication Process: Multi-Factor Authentication â The script created Application Passcodes to bypass 2FA (âCreateAppSpecificPasswordRequestâ).
- [T1074.002] Data Staged: Remote Data Staging â Exfiltrated data was first stored on actor-controlled VPS infrastructure (âstores the data in an actor-controlled ⌠VPSâ).
- [T1048.003] Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol â Smaller payloads were exfiltrated through DNS queries (âDNS A record queriesâ).
- [T1560] Archive Collected Data â Emails were exfiltrated as a GZIP compressed archive (âsent it as a GZIP compressed archiveâ).
- [T1114.003] Email Collection: Remote Email Collection â Emails were pulled from the mail server via requests rather than from local storage (âcollected via API calls to the ZCS mail serverâ).
- [T1090.002] Proxy: External Proxy â Mullvad VPN functioned as proxy-like infrastructure to obscure origin (âto mask their identityâ).
Indicators of Compromise
- [Domains ] Flowerbed/Catcher infrastructure domains used for exfiltration and staging â zmailanalytics[.]com, zimbra-metadata[.]com, and 7 more domains
- [IP addresses ] Associated with Flowerbed server infrastructure â 216.252.238[.]104, 216.252.238[.]18, and 7 more IPs
- [SHA-1 hashes ] Letâs Encrypt certificate hashes tied to Flowerbed infrastructure â 2e4f314bc9943cab5005d6fde0b271c74d47bc9d, 50a87d926621dd06389ba50d86e0ff574ed713a8, and 8 more hashes
- [Email addresses ] Addresses used to procure resources for the campaign â ivanka.zurabishvili@proton[.]me, zmul1@buildandconsulting[.]com, and 2 more addresses
- [Email addresses ] Addresses used to distribute malicious payloads â c.laurent.ejfa@proton[.]me, j.moreau.epsc@proton[.]me, and 3 more addresses
- [SHA-256 hashes ] Malicious email samples containing the payload â 98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf, 60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874, and 2 more hashes
- [File paths ] ZCS logs and local artifacts useful for detection â /opt/zimbra/log/mailbox.log, window.top.localStorage
- [File names ] Exfiltration and telemetry artifacts written by Catcher â zimbra_batch_analytics.json, telemetryData_{0-89}.json
- [HTTP path / content ] Exfiltration endpoint and content patterns â /v/p, pixel.gif
- [Certificate names ] HTTPS wildcard certificates used by Flowerbed â *.i.zmailanalytics[.]com, *.i.synacorzimbra[.]nl
- [Network infrastructure ] Named tools/services used in the campaign â Mullvad VPN, Letâs Encrypt, Cloudflare
Read more: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a