Russian hackers exploit Zimbra zero-click flaw for email theft

Russian hackers exploit Zimbra zero-click flaw for email theft
CISA says the Russian state-sponsored group Laundry Bear, also known as Void Blizzard, is targeting Zimbra Collaboration servers with phishing and the now-patched CVE-2025-66376 XSS flaw to steal email data and bypass MFA. The campaign has hit organizations across government, defense, education, energy, media, and NGOs, while exfiltrating stolen information through the group’s Flowerbed framework and AiTM phishing kits. #LaundryBear #VoidBlizzard #Zimbra #CVE202566376 #Flowerbed

Keypoints

  • Laundry Bear is exploiting the patched Zimbra CVE-2025-66376 flaw.
  • The attack uses malicious HTML emails that run JavaScript automatically.
  • Stolen data includes mailboxes, passwords, GAL data, and 2FA tokens.
  • The group uses DNS and HTTPS to send data to the Flowerbed framework.
  • CISA urges Zimbra users to patch, review IOCs, and revoke suspicious passcodes.

Read More: https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/