Russian state-aligned hackers in the Laundry Bear campaign are using zero-click phishing emails to target Zimbra Collaboration Suite users across the West, with evidence pointing to espionage activity rather than financial extortion. The operation has hit Ukrainian, U.S., NATO, and other government and commercial entities, prompting urgent patching guidance for Zimbra users. #LaundryBear #ZimbraCollaborationSuite #CVE-2025-66376 #Proofpoint #Unit42 #Ukraine #NATO
Keypoints
- Laundry Bear is targeting Zimbra webmail users with zero-click phishing emails.
- The attackers exploit CVE-2025-66376 using malicious JavaScript hidden in email messages.
- The campaign has targeted governments, defense, transportation, finance, and high science organizations.
- Officials believe the activity is linked to Russian government-backed espionage.
- Agencies urged Zimbra users to patch immediately or switch to another mail client.
Read More: https://therecord.media/zimbra-webmail-zero-click-phishing-russia-laundry-bear