Western cybersecurity and intelligence agencies have warned that the Russian state-sponsored hacking group Laundry Bear, also tracked by Microsoft as Void Blizzard, has been exploiting a vulnerability in Zimbra Collaboration email servers to steal sensitive emails from government organizations and other high-value targets. The campaign primarily focused on Ukraine before expanding to NATO member states and additional organizations in Europe and North America.
According to a joint advisory issued by the United States, the United Kingdom, Canada, Australia, the Netherlands, and several other allied nations, the attackers abused a recently patched Zimbra vulnerability identified as CVE-2025-66376. Cybersecurity researchers describe the technique as a “half-click” attack because victims do not need to click a malicious link or open an attachment. Simply opening a specially crafted phishing email is sufficient to trigger the exploit, allowing attackers to compromise the victim’s mailbox.
Unlike traditional phishing campaigns that rely on convincing users to interact with malicious content, this attack significantly lowers the barrier for compromise. Once the email is displayed in the vulnerable Zimbra web client, malicious code executes automatically within the user’s browser session, enabling the attackers to gain access to email data without requiring further interaction. Security researchers say this makes the campaign particularly dangerous because standard user awareness training offers little protection against this type of exploit.
Authorities said the campaign was first observed targeting Ukrainian organizations before expanding to government agencies, police departments, defense-related entities, and diplomatic organizations in NATO countries. Intelligence officials believe the operation was conducted for cyber-espionage purposes, with the primary objective of collecting sensitive communications rather than deploying ransomware or destructive malware.
Laundry Bear first came to public attention after Dutch intelligence agencies linked the group to the 2024 compromise of the Dutch National Police, an intrusion that exposed personal information belonging to police personnel. Since then, researchers have attributed multiple espionage campaigns to the group, which Microsoft tracks under the name Void Blizzard. U.S. authorities have also linked Laundry Bear to the Russian cybersecurity company Yutek-NN, and criminal charges have previously been filed against one of the company’s senior officials in connection with hacking activities. Russia has consistently denied involvement in state-sponsored cyber-espionage campaigns.
The Zimbra vulnerability exploited in the campaign has now been patched, and cybersecurity agencies are urging organizations running Zimbra Collaboration to install the latest security updates immediately. Administrators are also advised to review server logs for signs of suspicious activity, search for indicators of compromise provided in the joint advisory, and reset credentials if unauthorized access is suspected. Because the attackers focused on stealing email data, investigators recommend examining mailbox access records for unusual activity that may indicate successful exploitation.