Russian-Linked Hackers Exploit Zimbra Email Flaw in Espionage Campaign

Last updated: July 24, 2026 Reading time: 4 minutes
Disclosure
Share
  • Russian-linked hackers have targeted Western groups by abusing a Zimbra email flaw since July 2025.
  • The attack can start when victims simply view a harmful email, without clicking links or opening files.
  • The attackers reportedly steal emails, passwords, address books, two-factor tokens, and other account details.

Russian-linked hackers have spent at least a year targeting government and business networks. The attackers abused a flaw in Zimbra’s email software to reach their victims. The attack uses a new twist on common phishing methods. Victims do not need to click a link or open an attachment. Simply viewing a harmful email can start the attack.

Twenty-seven US, UK, and other international government agencies warned about the campaign. They linked the attacks to a group called Laundry Bear, also known as Void Blizzard. The joint security alert said the group likely wants sensitive information for Russia. The attackers mainly focus on secretly collecting email data from their targets.

Attackers Exploit Zimbra Email Flaw

The campaign targets a Zimbra flaw tracked as CVE-2025-66376. The flaw involves cross-site scripting, which can let attackers place harmful code inside web pages. Zimbra fixed the security problem in November 2025. However, the attackers had already used the flaw months earlier. The campaign began in July 2025, according to the government agencies.

The exploitation of software flaws is a common tactic. Adobe also fixed a Chrome extension vulnerability that exposed WhatsApp Web data.

The attackers sent harmful HTML emails to organizations across several important sectors. The targeted groups include defense companies and federal and local governments. Education, energy, law enforcement, media, and technology groups also faced attacks.

Non-government organizations also appeared among the targeted groups. The attackers used several email addresses during the campaign. The listed addresses include ivanka.zurabishvili@proton[.]me and zmul1@buildandconsulting[.]com. Other addresses include garrysmithme@pinmx[.]net and hostingclient@pinmx[.]net.

The attack does not need the victim to take extra action. Once the victim views the harmful email, the attackers can begin stealing information.

Hackers Steal Emails and Login Details

The attackers reportedly collected a wide range of information from affected organizations. This included the victims’ email messages from the previous 90 days. They also stole email addresses and passwords.

The attackers collected organization-wide email directories, including global address lists. The stolen information also included two-factor authentication tokens. The attackers reportedly gathered newly created app passwords as well. The group then used the stolen login details to keep access to victims’ email accounts. They also changed account settings and continued collecting authentication information. 

This method could allow attackers to remain inside accounts after the original attack. They could then use stolen details to gather more information from the same victims. The government agencies said Laundry Bear stored stolen data on a virtual private server.

The server could not be easily linked to the attackers. The group used its own data collection system, called Flowerbed, to manage the stolen information. Flowerbed is a Python project that uses Docker to run its different parts.

The government agencies also examined the Flowerbed code. They said the simple code showed signs that artificial intelligence may have helped create it. The joint security alert described the campaign as a serious effort to secretly collect email information. The agencies said the attackers focused on gaining access without alerting their victims.

Security Alert: List Signs of Compromise

The attack stands out because victims only need to view the harmful email. They do not need to click anything or open a file for the attack to begin. That makes the campaign different from many common phishing attacks. In many cases, victims must click a link or open an attachment before attackers can act.

The Laundry Bear campaign instead uses a flaw in the email system itself. This gives the attackers a way to target users through messages they simply view. The 31-page government security alert contains a long list of indicators of compromise. Organizations can use these details to check whether their networks or users may have been affected.

The agencies advised organizations to review the listed signs carefully. They can use the information to identify people who may have fallen victim to the campaign. The joint alert also provides details about the attack methods and the systems involved. 

Security teams can use those details when checking their email systems for signs of unauthorized access. The campaign shows how attackers can use flaws in trusted email tools to reach large organizations.

It also highlights the risks that can appear when security flaws remain open before patches become available. For the affected organizations, the main concern remains stolen email data and account access.

The attackers reportedly collected sensitive information and used stolen credentials to maintain access. The agencies’ warning gives organizations information they can use to search for signs of compromise. They can also review the listed indicators to determine whether attackers may have entered their systems.

Share this article

About the Author

Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.

More from Farwa Sajjad

Related Posts