ARTICLE AD BOX
Opening an unexpected email can feel relatively harmless when you avoid its links and attachments. However, a Russian hacking campaign has turned that familiar safety advice on its head.
CISA says the Russian state-sponsored group Laundry Bear can compromise certain email accounts when someone simply opens or previews a malicious message. The attack targets organizations running unpatched versions of the Zimbra Collaboration Suite.
Once the email appears, hidden code can collect passwords, authentication data and as much as 90 days of messages. You may never see a warning or realize that anything happened.
The Cybersecurity and Infrastructure Security Agency issued the warning with the National Security Agency, FBI and cyber authorities from several allied countries. The agencies say the group has successfully targeted more than 10 Western organizations since July 2025.
CyberGuy Live: Missed "Sick of Spam?" Get the replay and checklist
Our free CyberGuy Live class, "Sick of Spam?" has ended, but you can still watch the full replay and download our spam-stopping checklist. Kurt "CyberGuy" Knutsson walks you step by step through simple ways to reduce robocalls, spam texts, junk email and unwanted messages. You’ll also learn how to curb political texts, clean up your inbox and spot messages that could put your personal information at risk.
Get the free replay and checklist now at CyberGuyLive.com.
Laundry Bear, which Microsoft tracks as Void Blizzard, exploits a security flaw known as CVE-2025-66376. The cross-site scripting vulnerability affects the Classic user interface in certain versions of the Zimbra Collaboration Suite.
Zimbra is an email and collaboration platform used by some governments, schools, businesses and other organizations as an alternative to services such as Microsoft Exchange or Google Workspace. Attackers can place malicious JavaScript inside a specially crafted HTML email. That code runs automatically when a vulnerable Zimbra webmail client displays the message.
The person reading the email does not need to open an attachment. The attack also avoids the usual request to enter a password on an obvious phishing page. However, the email still needs to appear on the screen. CISA describes the technique as a zero-click exploit. Proofpoint calls it a "half-click" attack because someone must open the email or allow it to appear in a preview pane. Either description leads to the same concern. A message can look harmless while code hidden inside it quietly attacks the email account.
Laundry Bear reportedly used the flaw as a zero-day before Zimbra released a patch in November 2025. A zero-day attack exploits a security weakness before the software maker provides a fix. CISA later added the vulnerability to its list of flaws that hackers actively exploit.
The available patch closes the known security hole. Yet Laundry Bear continues to target organizations that have not installed the update. That makes delayed patching especially dangerous. An organization may have strong passwords and trained employees, but an exposed email server can still give attackers another way inside.
The campaign has reached organizations connected to the defense industrial base and government. Attackers have also targeted education, energy, law enforcement, media, nonprofit groups and technology companies.
According to CISA, the malicious code attempts to collect the target's last 90 days of email. That could include private conversations with coworkers, contract discussions or information about upcoming meetings. An inbox may also contain password reset notices, invoices and documents that reveal how an organization operates.
Laundry Bear also collects the person's email address and password. The attack can copy the organization's Global Address List, which acts as a directory of employees and contacts. The hackers may then gain enough information to impersonate a trusted coworker or identify more valuable accounts.
CISA says the exploit also targets two-factor authentication tokens. Those tokens help prove that someone has already completed an authentication step. A stolen token or session cookie can let an attacker enter an account without completing the normal login process again.
FAKE PASSWORD-MANAGER ALERTS COULD PUT YOUR VAULT AT RISK
Stealing information provides immediate value, but Laundry Bear also tries to preserve its access. The attack creates a new Zimbra application passcode and sends it back to the hackers. Legacy email programs use these passcodes when they connect through services such as IMAP or ActiveSync and cannot support modern time-based authentication.
An unauthorized passcode can give the hackers another entrance to the mailbox. That access may continue even after someone changes the main account password. CISA has urged administrators to look for suspicious application passcodes, particularly passcodes labeled "ZimbraWeb."
Organizations should treat an unknown passcode as a sign that someone may have entered the account. Simply installing the patch after a compromise may leave the attacker's access in place.
Laundry Bear sends the stolen information to servers controlled by the group. CISA says the attackers use a collection framework called Flowerbed. The system moves smaller pieces of data through Domain Name System requests. DNS normally helps computers find websites and online services.
Attackers can hide encoded information inside those requests. Because organizations generate large amounts of legitimate DNS traffic, the malicious activity may blend into the background. Laundry Bear sends larger collections through encrypted HTTPS connections. That can include compressed archives containing mailbox data. Security teams may need to inspect network logs, authentication records and mailbox activity to understand what left the organization.
Laundry Bear also uses adversary-in-the-middle phishing kits. These tools create login pages that closely resemble legitimate email portals. When someone enters a username and password, the phishing system captures those credentials. It can also intercept session cookies created during the login process. That means an attacker may gain access even when the account uses conventional multifactor authentication.
CISA's indicators of compromise include domains that impersonated Zimbra infrastructure. Examples include mailnalysis.com, zimbrastat.com, zimbra-metadata.com and zmailanalytics.com. The presence of one of these domains in network logs could point to phishing or unauthorized account activity. However, organizations should review CISA's complete list because attackers can change their infrastructure.
Proofpoint found that Laundry Bear sent messages from attacker-controlled Proton Mail accounts and email addresses the group had already compromised. In one example, the sender claimed to represent a Belgian media-verification organization. The email proposed cooperation between European institutions fighting disinformation. It included a legitimate-looking link to a European Union events calendar. However, the malicious code sat inside the email rather than the linked website.
Dutch intelligence agencies publicly identified Laundry Bear in May 2025. Their investigation linked the group to a 2024 breach of the Dutch National Police. That incident exposed personal information belonging to police personnel. Investigators said the attack helped them identify a previously unknown Russian cyberespionage group.
Since at least 2024, Laundry Bear has focused on organizations connected to Russian strategic interests. Its targets have included NATO member states and groups supporting Ukraine.
Microsoft has documented compromises involving defense organizations as well as entities in transportation and aviation.A separate campaign targeted members of Ukraine's military with charity-themed phishing emails. Those messages disguised malware as requests for donations.
These campaigns suggest the group cares more about long-term intelligence collection than a quick financial payout. Access to email can reveal relationships, future plans and internal decisions.
PAIDWORK BREACH EXPOSES 23M USER RECORDS
The strongest protection starts with the organization running the email server because employees cannot personally patch a vulnerable installation. However, you can still take steps to spot suspicious activity and protect your other accounts.
Administrators should update Zimbra Collaboration Suite to a currently supported version and install all available security fixes. Organizations should confirm that the patch reached every server. An overlooked system may remain exposed even when the primary mail server has received the update.
Installing the patch blocks the known flaw, but it cannot undo a previous intrusion. Security teams should review CISA's published indicators of compromise. They should also search network records for connections to the listed domains and IP addresses. Authentication logs may reveal unusual locations, unexpected devices or activity outside normal working hours.
Review every Zimbra application passcode connected to an account. Pay close attention to unfamiliar entries and anything labeled "ZimbraWeb." Revoke any passcode that the account owner or IT department cannot verify. Because application passcodes can survive a regular password change, this review plays an important role in removing persistent access.
Administrators should examine mailbox access records and forwarding settings. They should also look for unfamiliar filters, deleted messages or sent emails that the account owner does not recognize. A compromised account may send convincing phishing messages to coworkers because the email comes from a trusted internal address.
Contact your IT or security team if you notice unfamiliar sent messages, unexpected password resets or login alerts you cannot explain. Do not rely only on changing your password. Laundry Bear can create an application passcode that may continue providing mailbox access after the main password changes. Your IT team should revoke unauthorized passcodes, end active sessions and check the account for suspicious activity.
Wait until your IT department has patched the server and removed unauthorized access. Then change your email password and any other password you reused. Create a unique password for every account. A password manager can generate strong credentials and store them securely. Hackers may test stolen email credentials on banking, shopping or social media accounts. Reused passwords can turn one compromised inbox into several compromised accounts.
CISA recommends phishing-resistant multifactor authentication where organizations can support it. Security keys and passkeys provide stronger protection than methods that rely on temporary codes. However, organizations still need to patch the underlying email software. Authentication controls cannot fully protect an account when malicious code runs inside a vulnerable webmail interface.
Strong antivirus software can help detect malicious downloads, fake login pages and follow-up malware connected to a broader phishing campaign. However, antivirus software may not stop this email exploit because the malicious code runs inside a vulnerable webmail session. Your organization still needs to update Zimbra and investigate the account for unauthorized access. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.
An email login page can look convincing and still belong to an attacker. Instead of following a link inside an email, open your organization's known webmail address directly. Report unfamiliar authentication requests or repeated sign-in prompts to your security team. A sudden request to log in again could signal a phishing attempt or unauthorized account activity.
For years, we have warned you to avoid suspicious links and unexpected attachments. That advice still helps, but Laundry Bear shows why your organization also needs to keep the software behind your inbox updated. In this campaign, viewing an email can trigger malicious code on an unpatched server. The attackers can then reach into the mailbox, collect months of messages and steal authentication data. The hidden application passcode adds another concern. Changing a password may provide a false sense of security when an attacker has already created a separate route back into the account. Organizations using Zimbra should patch immediately and then investigate for signs of earlier access. Employees should remain cautious around unexpected login pages, even when the page carries familiar company branding.
Would you trust your workplace inbox if opening one message could expose 90 days of email without you clicking a link? Let us know by writing to us at CyberGuy.com.
Sign up for my FREE CyberGuy Report
Copyright 2026 CyberGuy.com. All rights reserved.

47 minutes ago
1







English (US) ·