Russian Laundry Bear group exploits Zimbra zero-day to steal email and 2FA codes

US agencies warn that Russian APT group Laundry Bear is actively exploiting CVE-2025-66376 against unpatched Zimbra Collaboration servers worldwide.

CSBadmin
2 Min Read

Russian state-sponsored threat group Laundry Bear is actively exploiting a Zimbra zero-day vulnerability to steal email contents and two-factor authentication codes from unpatched servers, US and international agencies warned in a joint advisory published Thursday.

The campaign exploits CVE-2025-66376, a cross-site scripting flaw in Zimbra Collaboration Suite that allows malicious JavaScript embedded in HTML emails to execute automatically when viewed in the webmail client. The attack requires no user interaction beyond opening the message, making it a zero-click exploit vector that bypasses traditional phishing defenses.

Laundry Bear, also tracked as Void Blizzard, sends phishing emails from previously compromised accounts to evade detection. The emails contain Base64-encoded JavaScript payloads hidden within SVG elements, delivered through abused CSS @import directives. Once executed, the malware enables IMAP access to the victim’s mailbox, creates application passwords, harvests saved browser credentials, and extracts 2FA codes from authenticator sessions.

The group exfiltrates collected data through HTTPS and DNS channels to attacker infrastructure dubbed Flowerbed. CISA, the NSA, the FBI, and international partners published indicators of compromise including the domains mailnalysis.com, zimbrastat.com, and zmailanalytics.com used by the attackers. Organizations running Zimbra should update to the latest version immediately, review authentication logs for anomalies, and revoke unauthorized application passcodes.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.