Quick Links

    Decian blog

    Threat Advisories

    LAUNDRY BEAR and the Zimbra Zero-Day: What Mid-Market Teams Need to Know

    Jake McDowell ยท 2026-07-27

    A sophisticated Russian state-supported group identified as LAUNDRY BEAR is actively targeting organizations using Zimbra Collaboration Suite (ZCS). This campaign represents a notable escalation in threat actor capabilities, as the group has moved from social engineering and password spraying to exploiting a novel zero-day vulnerability. The advisory details that this activity began in July 2025, well before the official patch was released, highlighting the group's ability to operationalize unknown exploits quickly.

    The mechanics of this attack are particularly concerning for IT teams relying on Zimbra for their email infrastructure. Unlike traditional phishing where a user must click a link or open an attachment, this campaign exploits a vulnerability in the webmail rendering engine. The exploit, tracked as CVE-2025-66376, allows an attacker to execute malicious JavaScript simply by a victim opening and viewing an email. Once the payload executes, it initiates a silent extraction of the last 90 days of emails, the organization's global address list, authentication tokens, and application passcodes.

    For mid-market organizations, the risk is amplified by the sheer volume of data accessible through this single vector. The group has demonstrated a clear intent to gather intelligence for the Russian Federation rather than seeking financial gain through extortion. They deploy a custom framework called Ulej to aggregate data and exfiltrate it through both DNS and HTTPS channels. The exfiltrated data is stored on compromised infrastructure before being moved to long-term retention servers, leaving little trace for defenders to catch in real-time.

    The sophistication of this group is evident in their operational choices. They use automated infrastructure that rotates servers frequently and employ AI-assisted development to generate new payload variants. This suggests that reliance on static signatures or traditional perimeter defenses alone will not be sufficient to stop these actors. The group also abuses legitimate administrative functions within Zimbra, such as SOAP requests, to maintain persistence and bypass multi-factor authentication by creating application-specific passcodes.

    Immediate action is required for any organization running Zimbra Collaboration Suite. The vulnerability has been patched in recent updates for versions 10.1.13 and 10.0.18. However, until patches are applied, the risk of unauthorized access remains critical. Teams must assume that if their systems have not been updated since mid-2025, they are likely compromised or at high risk.

    Here are the essential steps IT leaders and security practitioners should take immediately:

    The shift to exploiting vulnerabilities in widely used email software underscores the need for a proactive security posture. Relying solely on user training is no longer enough when the threat can execute code without any user interaction. Continuous monitoring of email infrastructure and rapid patch management are the primary defenses against this type of espionage-driven threat.

    Decian provides managed SOC and MDR services designed to detect and respond to these sophisticated attacks. Our team can help mid-market organizations secure their email infrastructure, monitor for indicators of this campaign, and manage incident response if a compromise is detected. Learn more about how we can support your security operations at www.decian.com.

    ยฉ 2025 Decian, Inc. All rights reserved.