HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 27.07.2026 09:39 CET 44 dossiers MITRE ATT&CK mapping

LAUNDRY BEAR — Russian state APT (joint CISA/NSA/FBI advisory AA26-204a)high

LAUNDRY BEAR: the Russian zero-click that empties Zimbra mailboxes

On 23 July 2026 CISA, NSA, FBI and international partners published a joint advisory on LAUNDRY BEAR, a Russian state-supported APT group targeting users of Zimbra Collaboration Suite. The dangerous novelty is the mechanism: not a link to click, but a zero-click exploit that triggers simply when a user views a malicious email in a vulnerable version of the webmail. The group uses a custom-built tool called Ulej to aggregate and exfiltrate data, exploiting CVE-2025-66376. Since July 2025 more than ten organisations have been hit: email addresses, passwords and 2FA tokens stolen.

An email that asks you to click nothing

The phishing we have all learned to spot has an implicit rule: somewhere there is an action to take. A link to open, an attachment to download, a "verify your account" button. The campaign described on 23 July 2026 in the joint advisory from CISA, NSA, FBI and international partners breaks that rule. The group — a Russian state APT the agencies call LAUNDRY BEAR — uses a zero-click exploit: it is enough for the user to view a malicious email inside a vulnerable version of the Zimbra Collaboration Suite webmail. No click, no attachment opened. The mailbox opens, and the damage is already under way.

It is a difference that matters, because it shifts the whole weight of defence away from the user's caution and onto software updates. No anti-phishing training holds against an attack that asks the user to do nothing.

  1. 01
    Malicious email arrives
    crafted for a vulnerable ZCS webmail
  2. 02
    View alone
    the zero-click exploit fires when the message is opened
  3. 03
    Ulej goes to work
    it aggregates and exfiltrates the mailbox data

What leaves the mailbox, and who wants it

According to the advisory, LAUNDRY BEAR exploits CVE-2025-66376 in Zimbra and uses a custom-developed capability called Ulej to aggregate and exfiltrate information. The loot is not generic: the agencies explicitly cite email addresses, passwords, and two-factor authentication tokens. Stealing the second factor, not just the password, is what lets an attacker slip past the defences most organisations now consider sufficient.

Since July 2025, the advisory reports, more than ten organisations using ZCS have been successfully compromised. And the target list is why this is a matter of national cybersecurity rather than IT news: the Defense Industrial Base, federal and local government, law enforcement, technology companies, universities, media, and non-governmental organisations. It is the classic profile of intelligence collection — email as a mine of relationships, documents and credentials, to be worked for weeks.

CVE-2025-66376
the exploited flaw
in Zimbra Collaboration Suite
10+
organisations hit
since July 2025, per the advisory
3
the target data
email, passwords and 2FA tokens

Why zero-click changes the priorities

Chris Butera, CISA's acting cybersecurity chief, framed the point well: state groups, more and less sophisticated, are turning novel exploits into concrete capabilities for espionage and for hitting infrastructure. Against an exploit that triggers on merely reading a message, the countermeasure is not behavioural but technical, and the advisory is blunt about which one: promptly update all ZCS mail service software and continuously monitor mailboxes and messages for malicious activity. Anyone who finds indicators of compromise in their environment must follow the specific remediation actions in the advisory, not just install the patch.

Two things should be said honestly here. First: the attribution to a Russian state actor is that of the joint advisory, signed by CISA, NSA, FBI and partners — the most authoritative source available, but still an agency attribution, not a fact a reader can verify independently. Second: the advisory notes that LAUNDRY BEAR's capability could be adapted to exploit other vulnerabilities too, so treating CVE-2025-66376 alone as "the problem" and closing it there would be a mistake in perspective. The campaign is described as ongoing.

The practical point remains, valid well beyond Zimbra: an internet-facing mail server is an extremely high-value target, and an unpatched webmail service is a door that opens on its own. The defence is not exotic — timely patching, monitoring, and the awareness that the second factor, once stolen, no longer protects. Zero-click does not make the attacker invincible: it simply makes it pointless to wait for the user to slip up.

More dossiers