The United States Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning concerning the activities of the Russian state-sponsored hacking group known as Laundry Bear, also identified as Void Blizzard. This sophisticated cyberespionage outfit is actively targeting organizations that rely on Zimbra Collaboration email servers. Their modus operandi involves a potent combination of highly targeted phishing attacks and the exploitation of a critical, albeit now patched, vulnerability within the Zimbra Collaboration Suite’s Classic User Interface, specifically CVE-2025-66376. This cross-site scripting (XSS) flaw, when exploited, allows for the automatic execution of embedded JavaScript within specially crafted HTML emails. This bypasses the need for user interaction, such as clicking malicious links or visiting compromised websites, to compromise account data. The ongoing exploitation of this vulnerability underscores a persistent threat to organizations across vital sectors, including the Defense Industrial Base (DIB), federal and local governments, educational institutions, energy providers, law enforcement agencies, media outlets, non-governmental organizations, and technology companies.
The scope of Laundry Bear’s targets indicates a strategic focus on intelligence gathering and disruption, aligning with broader Russian geopolitical objectives. The group’s consistent targeting of entities associated with the Defense Industrial Base and government sectors suggests a deliberate effort to gain insights into sensitive defense strategies, technological advancements, and governmental operations. The inclusion of educational and non-governmental organizations hints at a broader interest in influencing public discourse, gathering information on research initiatives, or potentially recruiting assets.
Chronology of Exploitation and Awareness
CISA’s alert highlights that Laundry Bear leveraged CVE-2025-66376 as a zero-day vulnerability, meaning it was actively exploited by the group before Zimbra officially became aware of and subsequently patched the flaw in November 2025. This proactive exploitation by a state-sponsored actor underscores the significant lead time such groups often possess in identifying and weaponizing software weaknesses. The subsequent tagging of this vulnerability by CISA as "actively exploited" served as a critical call to action for organizations globally, emphasizing the immediate and ongoing risk.
The exploitation of this XSS vulnerability is particularly insidious. When a victim user views a specially crafted email, the embedded JavaScript executes automatically. This allows attackers to directly steal sensitive account information, including credentials, without any overt action from the user. This method bypasses traditional security measures that rely on user awareness of phishing attempts, such as scrutinizing sender addresses or avoiding suspicious links.
The Mechanics of the Attack and Data Exfiltration
Beyond the initial compromise, Laundry Bear’s attack chain is designed for persistent access and comprehensive data theft. Upon successful exploitation of the Zimbra vulnerability, the attackers’ exploit automatically collects and transmits a wealth of data. This includes the victim’s email history for the preceding 90 days, their primary email address, password, the organization’s Global Address List (GAL), and crucially, any active two-factor authentication (2FA) tokens.
A particularly concerning aspect of the exploit is the method used to maintain access even when Multi-Factor Authentication (MFA) is in place. The attackers are capable of generating and transmitting a new Zimbra application passcode. This passcode is then utilized by legacy email clients that do not support modern authentication flows, such as those relying on IMAP or ActiveSync protocols. By leveraging these passcodes, Laundry Bear can effectively bypass MFA protections, retaining access to compromised email accounts and continuing their espionage operations without triggering immediate alerts associated with standard MFA failures. This technique highlights the sophisticated understanding the group possesses of various authentication mechanisms and their potential weaknesses.
The exfiltration of the stolen data is managed through a dual-channel approach, utilizing both DNS and HTTPS. Smaller data packets are encoded and transmitted within DNS A-record queries, a method that can be difficult to detect amidst normal network traffic. Larger payloads, including the extensive mailbox data, are compressed into archives and uploaded over HTTPS to servers controlled by the threat actor. This strategy ensures that even substantial amounts of sensitive information can be siphoned off without raising immediate red flags, further complicating detection efforts.

Complementary Tactics: AiTM Phishing Kits
In addition to exploiting the Zimbra vulnerability, Laundry Bear employs a complementary tactic: Adversary-in-the-Middle (AiTM) phishing kits. These kits are meticulously designed to impersonate legitimate Zimbra login portals, creating highly convincing fake websites. The objective is to trick users into submitting their credentials and session cookies directly to the attackers. Once captured, these credentials and cookies allow Laundry Bear to gain unauthorized access to the target’s email accounts, often bypassing MFA altogether by hijacking active sessions.
CISA has provided Indicators of Compromise (IOCs) that shed light on the infrastructure used in these campaigns. These IOCs include domain names that mimic legitimate Zimbra infrastructure, such as ‘mailnalysis.com’, ’emailanalytics.com.ua’, ‘zimbrastat.com’, ‘zimbra-metadata.com’, ‘istc-cloud.com’, and ‘zmailanalytics.com’. The use of country-code top-level domains (ccTLDs) like ‘.ua’ further suggests a potential operational focus or origin, though such domains can also be used for obfuscation. The consistent theme in these domain names – analysis, metadata, statistics, and cloud – is designed to appear as legitimate service providers related to email management, thereby increasing the likelihood of user deception.
Official Responses and Recommendations
CISA’s advisory serves as a critical alert, urging organizations to take immediate action. While the provided text omits the specific recommended actions from CISA, typical recommendations in such scenarios include:
- Patching and Updates: Organizations using Zimbra Collaboration Suite are strongly advised to ensure their servers are updated to the latest patched versions that address CVE-2025-66376 and any other disclosed vulnerabilities. This is the most fundamental and effective defense against known exploits.
- Vulnerability Scanning: Regularly scan networks for instances of unpatched Zimbra servers and other potentially vulnerable software.
- Email Security Enhancements: Implement advanced email filtering solutions that can detect and block malicious HTML emails and sophisticated phishing attempts. This includes technologies that analyze email content for suspicious JavaScript or rendering anomalies.
- User Education and Awareness: Conduct regular and comprehensive cybersecurity awareness training for all employees. While the exploit bypasses direct user interaction for execution, education remains vital for recognizing the initial phishing lures and reporting suspicious activities.
- MFA Implementation and Strengthening: CISA explicitly recommends implementing phishing-resistant multi-factor authentication where possible. This means favoring MFA methods that are less susceptible to compromise, such as hardware tokens or authenticator apps over SMS-based MFA, which can be vulnerable to SIM-swapping attacks.
- Incident Response Planning: Develop and regularly test robust incident response plans to effectively handle potential breaches, including containment, eradication, and recovery.
- Monitoring and Logging: Enhance network and system monitoring to detect unusual activity, such as unexpected data exfiltration over DNS or HTTPS, or the creation of unusual application passcodes.
The proactive nature of CISA’s warnings and the detailed IOCs provided are crucial for enabling organizations to bolster their defenses and detect ongoing malicious activities.
Laundry Bear: A Persistent Threat Actor
The Laundry Bear (Void Blizzard) group has been a subject of concern for cybersecurity agencies for several years. The Dutch intelligence agencies first publicly attributed cyberespionage activities to this group in May 2025. Their investigation linked Laundry Bear to a significant 2024 compromise of the Dutch National Police. This breach not only exposed the personal information of police personnel but also led to the identification of a previously unknown Russian espionage group, highlighting the evolving nature of state-sponsored cyber threats.
Microsoft, a prominent cybersecurity firm, tracks the same entity under the moniker Void Blizzard. Their analysis corroborates the findings regarding Laundry Bear’s operational focus and strategic objectives. Since at least 2024, the group has consistently prioritized intelligence collection against organizations perceived to be aligned with Russian strategic interests. This has primarily translated into targeted attacks against NATO member states and Ukraine, reflecting the ongoing geopolitical tensions and cyber warfare landscape.
Microsoft has documented successful compromises by Void Blizzard against organizations that provide critical support to Ukraine. This includes entities operating within the defense, transportation, and aviation sectors. These targets underscore the group’s objective of disrupting or gaining insights into the logistical and military support networks bolstering Ukraine’s defense efforts.

Earlier in 2025, BleepingComputer reported on a separate Laundry Bear campaign that specifically targeted Ukraine’s military. This campaign employed a charity-themed phishing campaign, leveraging a common and often effective social engineering tactic. Malware was disguised within seemingly legitimate donation requests, aiming to infiltrate the Ukrainian armed forces’ networks. This pattern of activity—utilizing both technical vulnerabilities and sophisticated social engineering—demonstrates Laundry Bear’s adaptability and broad range of offensive capabilities.
Broader Implications and Analysis
The sustained and sophisticated operations of Laundry Bear, as detailed by CISA and other security researchers, highlight several critical implications for the global cybersecurity landscape. Firstly, it underscores the persistent and evolving threat posed by state-sponsored hacking groups. These actors possess significant resources, technical expertise, and strategic patience, allowing them to conduct long-term espionage campaigns and exploit even subtle vulnerabilities.
Secondly, the reliance on Zimbra Collaboration Suite by a wide array of organizations, including those in critical infrastructure and government, makes it a significant target. The exploitation of a single vulnerability like CVE-2025-66376 can have cascading effects, compromising numerous entities simultaneously. This emphasizes the importance of supply chain security and the need for vendors to maintain rigorous security practices and rapid patching cycles.
Thirdly, the combination of zero-day exploits and advanced phishing techniques, such as AiTM kits, represents a potent attack vector. This dual approach allows attackers to exploit technical weaknesses while also leveraging human susceptibility, making defenses more challenging. The ability to bypass MFA through the use of application passcodes for legacy clients is a particularly concerning development, indicating that even widely adopted security measures may have exploitable blind spots.
The exfiltration methods, utilizing DNS and HTTPS, further demonstrate the attackers’ efforts to remain undetected. These techniques are designed to blend in with legitimate network traffic, making them harder to distinguish from normal operations. This necessitates advanced threat detection capabilities that go beyond signature-based approaches, focusing on behavioral analysis and anomaly detection.
The consistent targeting of entities related to NATO and Ukraine reinforces the understanding that cyber operations are an integral component of modern geopolitical strategy. The intelligence gathered through these campaigns can provide significant strategic advantages, influencing decision-making and shaping outcomes in ongoing conflicts and international relations.
In conclusion, the CISA advisory on Laundry Bear’s exploitation of Zimbra Collaboration servers serves as a critical reminder of the persistent and evolving threats emanating from state-sponsored actors. The group’s sophisticated tactics, combining technical exploits with advanced social engineering, necessitate a multi-layered and proactive cybersecurity strategy. Organizations across all sectors must remain vigilant, ensuring their systems are patched, their defenses are robust, and their personnel are well-educated to counter the ever-present danger of cyber espionage. The ongoing battle against such sophisticated adversaries requires continuous adaptation, intelligence sharing, and a commitment to strengthening cybersecurity resilience at all levels.







