Ninety days of archived email, along with passwords and two-factor authentication tokens, flows to attacker-controlled servers the moment a vulnerable Zimbra webmail client renders a malicious message, according to a joint advisory from CISA, the NSA, the FBI and allied cyber authorities. The operation belongs to Laundry Bear, a Russian state-sponsored group Microsoft tracks as Void Blizzard. More than 10 Western organizations have been hit since July 2025.
CVE-2025-66376: how the exploit runs
The flaw is a cross-site scripting vulnerability in the Classic user interface of certain Zimbra Collaboration Suite versions. Zimbra serves governments, schools, businesses and other organizations as an alternative to Microsoft Exchange or Google Workspace. Laundry Bear embeds malicious JavaScript inside specially crafted HTML emails; that code executes automatically when a vulnerable Zimbra browser session displays the message. No attachment opened, no link clicked. CISA labels the technique a zero-click exploit. Proofpoint calls it a "half-click" attack because the email must reach the screen, whether fully opened or visible in a preview pane.
The group treated CVE-2025-66376 as a zero-day before Zimbra released a patch in November 2025. CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalog. Organizations that skipped the update remain fully exposed.
What the attackers collect and how they stay in
The malicious code targets four categories: up to 90 days of mailbox content, the account's email address and password, the organization's Global Address List, and active session cookies or authentication tokens. A stolen session token lets attackers re-enter an account without completing a new login. Laundry Bear also generates a fresh Zimbra application passcode, which legacy clients use to connect via IMAP or ActiveSync when modern time-based authentication is unavailable. CISA has specifically flagged passcodes labeled "ZimbraWeb." Because application passcodes survive a standard password reset, attacker access can persist long after a user believes the account is secured.
Stolen data exits through Flowerbed, a collection framework that encodes smaller payloads inside DNS requests, blending into normal DNS traffic volume. Larger mailbox archives leave via encrypted HTTPS.
Target sectors and infrastructure
Laundry Bear has focused on organizations connected to Russian strategic interests since at least 2024. Confirmed sectors span defense, government, education, energy, law enforcement, media, nonprofits and technology. The group's targeting has concentrated on NATO member states and entities supporting Ukraine. Dutch intelligence agencies identified Laundry Bear in May 2025 after linking it to a 2024 breach of the Dutch National Police that exposed personnel data.
Proofpoint found the group sent phishing emails from attacker-controlled Proton Mail accounts and from addresses already compromised in earlier intrusions. CISA's published indicators of compromise include domains impersonating Zimbra infrastructure: mailnalysis.com, zimbrastat.com, zimbra-metadata.com and zmailanalytics.com.