Russian state-sponsored threat group Laundry Bear is actively exploiting a Zimbra zero-day vulnerability to steal email contents and two-factor authentication codes from unpatched servers, US and international agencies warned in a joint advisory published Thursday.
The campaign exploits CVE-2025-66376, a cross-site scripting flaw in Zimbra Collaboration Suite that allows malicious JavaScript embedded in HTML emails to execute automatically when viewed in the webmail client. The attack requires no user interaction beyond opening the message, making it a zero-click exploit vector that bypasses traditional phishing defenses.
Laundry Bear, also tracked as Void Blizzard, sends phishing emails from previously compromised accounts to evade detection. The emails contain Base64-encoded JavaScript payloads hidden within SVG elements, delivered through abused CSS @import directives. Once executed, the malware enables IMAP access to the victim’s mailbox, creates application passwords, harvests saved browser credentials, and extracts 2FA codes from authenticator sessions.
The group exfiltrates collected data through HTTPS and DNS channels to attacker infrastructure dubbed Flowerbed. CISA, the NSA, the FBI, and international partners published indicators of compromise including the domains mailnalysis.com, zimbrastat.com, and zmailanalytics.com used by the attackers. Organizations running Zimbra should update to the latest version immediately, review authentication logs for anomalies, and revoke unauthorized application passcodes.

