Decian blog
Threat Advisories
Russian APT Targets Zimbra: What Mid-Market Leaders and MSPs Must Do
A sophisticated Russian state-supported threat group known as LAUNDRY BEAR has launched a targeted campaign against organizations using the Zimbra Collaboration Suite (ZCS). This activity has been ongoing since at least July 2025 and focuses on the covert theft of sensitive email data from Western government and commercial entities.
What makes this threat particularly dangerous for mid-market organizations is the method of delivery. Unlike traditional phishing that requires a user to click a link or open a file, this campaign exploits a view-based vulnerability. An attacker only needs a user to load the malicious email within a vulnerable Zimbra webmail interface for the exploit to trigger.
The group utilized a zero-day vulnerability, now identified as CVE-2025-66376, which was patched in November 2025. Once the exploit is triggered by viewing the email, a JavaScript payload executes silently. This script proceeds to harvest the last 90 days of email communications, the organization's Global Address List, and authentication details like 2FA tokens and application passcodes. The data is then sent to infrastructure controlled by the attackers for long-term retention and analysis.
For mid-market IT leaders and MSP partners, the implication is clear. Many organizations may not have the resources for 24/7 specialized threat hunting. The sophistication of this campaign demonstrates that attackers are increasingly willing to deploy custom capabilities and zero-day exploits to bypass standard defenses. The absence of financial extortion in this specific campaign points directly to espionage activities driven by foreign state interests.
The group has been observed scanning for public-facing Zimbra instances and using compromised accounts to distribute further attacks. This self-propagation makes rapid patching and detection critical, as a single breach can serve as a springboard for wider compromise within an organization. The actors also demonstrated the ability to use artificial intelligence tools during the development of their malware, suggesting a continuous evolution of their technical capabilities.
Organizations must prioritize immediate patching of the ZCS platform. If immediate updates are not feasible, teams should advise users to switch to alternative mail clients to avoid the vulnerable web interface. Network monitoring should be enhanced to detect unusual outbound traffic patterns, specifically connections to known malicious virtual private servers or DNS queries to suspicious domains.
Here is a checklist of practical next steps for IT and security teams:
- Verify your Zimbra Collaboration Suite version and apply the latest security patches immediately.
- Review ZCS server logs for high volumes of SOAP requests, particularly those involving Global Address List searches or the creation of new application passcodes named "ZimbraWeb."
- Monitor network traffic for unusual outbound data transfers to unfamiliar IP addresses or domains.
- Conduct a scan for indicators of compromise (IOCs) in your environment, including specific domains and certificate hashes associated with the LAUNDRY BEAR campaign.
- Revoke all existing application passcodes and 2FA scratch keys for users who may have accessed the system during the active window of the campaign.
- Update password policies and require credential resets for affected users, assuming stored passwords in password managers may have been harvested.
This campaign highlights the persistent risk of supply chain and infrastructure-based vulnerabilities affecting essential communication tools. While no organization is immune, proactive monitoring and rapid response can significantly reduce the impact of such threats.
At Decian, we help mid-market organizations and their MSP partners navigate these complex threats with managed detection and response services tailored to your environment. If you are concerned about your exposure to vulnerabilities like this or need assistance hardening your email infrastructure, visit www.decian.com to learn more about our SOC and MDR solutions.