NG Solution Team
Cybersecurity

Zimbra exploit: did a Russian group steal sensitive data?

Since July 2025, a state‑backed Russian group has been exploiting a zero‑day in Zimbra Collaboration Suite to steal sensitive data from government and commercial organizations, U.S. authorities and cybersecurity officials from about fifteen countries warned in a joint advisory on Thursday.

Who’s behind the attacks
Authorities attribute the campaign to Laundry Bear, also tracked as Void Blizzard, an actor active since at least 2024. The advisory describes the activity as “covert and persistent” and notes there is no evidence of financial extortion, strongly indicating espionage operations supported by the Russian state. Identified targets span defense, education, energy, law enforcement, media, finance, transportation and technology sectors.

How the Zimbra exploit works and what was exfiltrated
The campaign leverages a vulnerability in Zimbra (CVE-2025-66376). The exploit is particularly dangerous because it requires “only a view — no click,” and allows attackers to retrieve, for the 90 days preceding the intrusion, emails, account passwords, search history, the organization directory, two‑factor authentication tokens and other newly created passwords. Operators also used a custom JavaScript payload delivered via phishing emails and developed a data‑extraction and aggregation capability dubbed “beehive,” which authorities believe could be adapted to other flaws.

Timeline and vendor/state response
Attacks began in July 2025; a patch for the vulnerability was not released until November 2025—roughly five months after the campaign started. Despite the patch, authorities say Laundry Bear continues to target unpatched Zimbra instances. The joint advisory was issued by the United States, Australia, Canada, New Zealand, the United Kingdom, the Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, the Netherlands, Poland, Spain and Sweden.

Security implications and recommended actions
Authorities emphasize that the vulnerability’s medium severity score (6.1) highlights the challenge defenders face when prioritizing patches solely by severity ratings. The campaign appears targeted and manual: operators identify organizations exposing public infrastructure, compile recipient lists, and send phishing emails designed to deliver the exploit.

The advisory includes indicators of compromise (IOCs) and mitigation guidance. Organizations are urged to apply available patches, review Zimbra logs and configurations for suspicious activity, and implement the following immediate steps:
– Confirm deployment of the patch for CVE-2025-66376.
– Analyze IOCs provided in the joint advisory.
– Increase monitoring of mailbox access and anomalous account activity.
– Verify the integrity of two‑factor authentication mechanisms and rotate credentials where compromise is suspected.
– Review email security controls and phishing defenses.

This campaign underscores that even vulnerabilities with moderate severity scores can enable high‑impact espionage when weaponized in targeted phishing operations. Organizations running Zimbra should prioritize patching and log review to detect and remediate possible compromise.

Related posts

Is there a hidden admin backdoor in Tenda routers allowing unauthorized remote access?

Michael Johnson

Are 100 universities at risk due to a PeopleSoft vulnerability?

David Jones

Has Craneware reported unauthorized access and file exfiltration? Alternatives: – Has Craneware suffered unauthorized access and file exfiltration? – Has Craneware experienced a data breach with file exfiltration?

Jessica Williams

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy