Security.io Intelligence DeskFriday, 7 August 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Threat Intelligence and Identity · Executive briefing

Laundry Bear’s Zimbra campaign turns a viewed email into mailbox persistence

A multinational advisory details a Russian state-supported campaign that executes malicious JavaScript when a user views an email in vulnerable Zimbra webmail, then steals mail, credentials and authentication material.

Email SecurityThreat IntelligenceIdentity
Read first

Government agencies from the United States, United Kingdom and partner countries have attributed an ongoing Zimbra-focused espionage campaign to the Russian state-supported group Laundry Bear. The operation exploits CVE-2025-66376, originally used as a zero-day, and can establish persistent mailbox

Act now

Verify that every Zimbra Collaboration Suite instance runs a release containing the CVE-2025-66376 fix, including the corrected 10.1.13 or 10.0.18 release lines identified in the advisory.

Accountable owner

CISO with the email platform owner, IAM leader, threat-intelligence team and affected business executives

Decision horizon

Determine exposure and patch state today; complete initial mailbox and identity hunting within 24 hours

AssessmentHigh confidence
Emerging riskNew exploit variants against patched Zimbra releases, migration to other webmail platforms, activity after February 2026 in vendor telemetry, or evidence that stolen accounts are being used for follow-on phishing and partner compromise.

What happened

A 31-page multinational advisory published on 23 July describes Laundry Bear, also tracked as Void Blizzard and TA488, exploiting CVE-2025-66376 against Zimbra Collaboration Suite. The flaw was used before its November 2025 patch and allows embedded JavaScript to execute when a targeted user views or previews a malicious email in the vulnerable Classic webmail client. No link click or attachment execution is required.

The Ulej or ZimReaper payload can gather recent email, contacts, passwords, 2FA scratch codes and environment data. It can create an application-specific password named ZimbraWeb for persistent IMAP, POP3 or SMTP access and use DNS and HTTPS channels for exfiltration. Proofpoint reports direct observations against Ukrainian, United States government, science and defence targets; its own telemetry had not observed activity after February 2026, while the government advisory says exploitation continues to succeed against unpatched systems.

Why this matters now

The campaign defeats the usual leadership assumption that phishing risk can be managed primarily through user behaviour. Viewing a message is enough, and compromised accounts are used to send subsequent messages, increasing trust and weakening gateway and awareness controls.

Patch deployment prevents the known client-side exploit but does not revoke application passwords, recover stolen authentication material or identify exported mail. The campaign therefore requires coordinated email, identity and data-exposure investigation rather than a software-only response.

The decision for security leaders

Make the first decision binary: either prove that all Zimbra systems were on a non-vulnerable release throughout the relevant period or begin a retrospective hunt. Where patching cannot be immediate, remove the vulnerable webmail experience from use.

Treat any ZimbraWeb application passcode, matching exploit email or high-risk SOAP sequence as a potential identity compromise. Revoke persistence, rotate credentials and determine whether the account sent messages to additional targets.

Assess the content and strategic sensitivity of affected mailboxes. Espionage impact can include negotiating positions, legal strategy, research, defence information and partner relationships even when no wider network intrusion is identified.

Evidence of closure

  • A version inventory showing that no reachable Zimbra instance remains on a vulnerable build.
  • Log-query results and analyst conclusions covering the commands, infrastructure and local-storage artefacts specified in the joint advisory.
  • Identity-system evidence that malicious application passcodes and authentication material were revoked and affected credentials replaced.
  • A mailbox-level exposure assessment identifying the users, dates and data potentially accessed.

The Security.io assessment

The decisive change is the breadth and authority of the disclosure. Multiple national agencies have provided technical detail, remediation steps and an attribution assessment, while Proofpoint supplies direct campaign telemetry and detection content. Confidence is high that the described exploitation and mailbox-theft technique is real; individual organisations must still establish whether they were targeted or compromised.

Security leaders should resist calling this only a legacy vulnerability. The current decision concerns persistence and information loss from exploitation that may have occurred before patching. Password resets alone are insufficient because application passcodes, 2FA material and browser or mailbox artefacts can support continued access or reveal the scope of theft.

The discrepancy between Proofpoint’s last directly observed activity and the government statement that exploitation continues should be interpreted as a difference in visibility, not proof that the campaign ended. Organisations should use the government advisory’s broader risk position until their own version history, logs, DNS data and mailbox evidence support a narrower conclusion.

Questions for the morning meeting

  • Which sensitive business, diplomatic, defence or legal conversations were accessible in potentially affected mailboxes?
  • Can the organisation revoke all forms of mailbox persistence rather than resetting passwords alone?
  • Are Zimbra logs and DNS telemetry retained for the period beginning in July 2025?
  • Which partners need warning if compromised accounts were used to send follow-on messages?

Related intelligence

Shared decision context

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Registration open
Sponsor's Notice · Information Security Network

Security.io Executive Roundtable: The 2027 CISO Agenda

CISO Roundtables & Executive events

View roundtables →
Invitation only
Sponsor's Notice · NoBrowser

Security.io CISO Dinner: The Secure Browser Decision

Virtual PC's & Secure Browsers in the Cloud

Request an invitation →
Black Hat week
Paid Placement · HackerFX

Security.io at Black Hat: Daily Intelligence Briefing

Catch the Daily News Where it Happens First

Follow the Black Hat desk →