Decian blog
Threat Advisories
LAUNDRY BEAR and the Zimbra Zero-Day: What Mid-Market Teams Need to Know
A sophisticated Russian state-supported group identified as LAUNDRY BEAR is actively targeting organizations using Zimbra Collaboration Suite (ZCS). This campaign represents a notable escalation in threat actor capabilities, as the group has moved from social engineering and password spraying to exploiting a novel zero-day vulnerability. The advisory details that this activity began in July 2025, well before the official patch was released, highlighting the group's ability to operationalize unknown exploits quickly.
The mechanics of this attack are particularly concerning for IT teams relying on Zimbra for their email infrastructure. Unlike traditional phishing where a user must click a link or open an attachment, this campaign exploits a vulnerability in the webmail rendering engine. The exploit, tracked as CVE-2025-66376, allows an attacker to execute malicious JavaScript simply by a victim opening and viewing an email. Once the payload executes, it initiates a silent extraction of the last 90 days of emails, the organization's global address list, authentication tokens, and application passcodes.
For mid-market organizations, the risk is amplified by the sheer volume of data accessible through this single vector. The group has demonstrated a clear intent to gather intelligence for the Russian Federation rather than seeking financial gain through extortion. They deploy a custom framework called Ulej to aggregate data and exfiltrate it through both DNS and HTTPS channels. The exfiltrated data is stored on compromised infrastructure before being moved to long-term retention servers, leaving little trace for defenders to catch in real-time.
The sophistication of this group is evident in their operational choices. They use automated infrastructure that rotates servers frequently and employ AI-assisted development to generate new payload variants. This suggests that reliance on static signatures or traditional perimeter defenses alone will not be sufficient to stop these actors. The group also abuses legitimate administrative functions within Zimbra, such as SOAP requests, to maintain persistence and bypass multi-factor authentication by creating application-specific passcodes.
Immediate action is required for any organization running Zimbra Collaboration Suite. The vulnerability has been patched in recent updates for versions 10.1.13 and 10.0.18. However, until patches are applied, the risk of unauthorized access remains critical. Teams must assume that if their systems have not been updated since mid-2025, they are likely compromised or at high risk.
Here are the essential steps IT leaders and security practitioners should take immediately:
- Apply the latest ZCS software updates to all instances to patch the zero-day vulnerability.
- Audit ZCS logs for high volumes of SOAP requests, specifically SearchGalRequest commands or CreateAppSpecificPasswordRequest entries named "ZimbraWeb".
- Review browser local storage on endpoints for entries matching the zd_comp_YYYY-MM-DD pattern used to track exfiltrated emails.
- Revoke all existing Application Passcodes and 2FA scratch keys across the organization and force a password reset for all users.
- Implement network monitoring to detect unusual outbound traffic to virtual private server (VPS) providers or frequent DNS queries to suspicious domains.
- Consider isolating ZCS webmail usage and directing users to alternative secure mail clients if immediate patching is not possible.
The shift to exploiting vulnerabilities in widely used email software underscores the need for a proactive security posture. Relying solely on user training is no longer enough when the threat can execute code without any user interaction. Continuous monitoring of email infrastructure and rapid patch management are the primary defenses against this type of espionage-driven threat.
Decian provides managed SOC and MDR services designed to detect and respond to these sophisticated attacks. Our team can help mid-market organizations secure their email infrastructure, monitor for indicators of this campaign, and manage incident response if a compromise is detected. Learn more about how we can support your security operations at www.decian.com.