State‑backed Russian group ‘Laundry Bear’ has been weaponising the Zimbra Collaboration Suite zero‑day (CVE‑2025‑66376) in a half‑click phishing campaign that only requires opening or previewing an email. The operation has targeted US government agencies, Ukrainian ministries and defense contractors.
Key Takeaways
- Russian APT ‘Laundry Bear’ leveraged Zimbra CVE‑2025‑66376
- Half‑click phishing needs only email view, no link click
- US, Ukraine, defense and research entities were primary targets
Russian state‑sponsored actors identified as “Laundry Bear” have been exploiting a zero‑day vulnerability in the Zimbra Collaboration Suite (ZCS) since July 2025. The flaw, catalogued as CVE‑2025‑66376, enables a “half‑click” exploit where merely opening or previewing a malicious email triggers arbitrary JavaScript execution on the victim’s webmail client.
Historical Background
Zimbra released a patch for the vulnerability in November 2025 (v10.1.13), but the CVE details were not publicly disclosed until weeks later. Initially described as a stored XSS issue in the Classic UI, the true impact—remote code execution via email preview—was only uncovered after multiple intelligence agencies reported active exploitation.
Why This Matters
BozokMedia analysis shows that the half‑click technique lowers the barrier for successful phishing, eliminating the need for users to click links or download attachments. This shift dramatically increases the attack surface for high‑value targets such as government ministries and defense contractors.
“Exploiting Zimbra’s XSS flaw allows attackers to harvest months of email data with a single preview, a capability that traditional phishing simply cannot match,” says cyber‑security analyst Dr. Anita Singh.
Frequently Asked Questions
- Is the attack still ongoing? While the specific “Laundry Bear” campaign appears to have ceased in early 2026, similar half‑click exploits could still be used against unpatched Zimbra installations.
- What steps should organizations take? Immediately upgrade to Zimbra 10.1.13 or later, consider alternative webmail clients, and restrict email preview functionalities where possible.