Russian Hackers Are Reading Your Email Just by Sending You One: Zimbra Zero-Day Explained
A Kremlin-linked crew tracked as LAUNDRY BEAR is exploiting CVE-2025-66376 in Zimbra webmail to steal 90 days of email the moment a victim opens a booby-trapped message.

Key points
- A Russian state-backed hacking group known as LAUNDRY BEAR has been breaking into Western government and corporate email since at least July 2025 by exploiting a flaw in Zimbra Collaboration Suite, a popular business email platform.
- The bug, tracked as CVE-2025-66376, was a zero-day when the attacks began and was patched by Zimbra in November 2025.
- The exploit fires when a target simply views a malicious email in the webmail window, with no click required.
- Once triggered, it steals the victim's last 90 days of email, the company address book, and other sensitive data, and tries to keep a foothold in the account.
- The warning comes from a joint advisory led by the U.S. National Security Agency, the FBI, CISA, and Dutch intelligence services AIVD and MIVD, co-signed by more than 20 agencies across Europe and the Five Eyes.
A Russian intelligence-linked hacking crew has spent the second half of 2025 quietly siphoning email out of Western governments and companies by abusing a previously unknown flaw in Zimbra webmail.
The group is best known as LAUNDRY BEAR, a name coined by Dutch military and civilian intelligence. Microsoft tracks the same crew as Void Blizzard. Palo Alto calls it CL-STA-1114. Proofpoint calls it TA488.
The vulnerability at the centre of the campaign is CVE-2025-66376, a bug in Zimbra Collaboration Suite (ZCS), the webmail and calendar platform used by a lot of government agencies, universities and mid-sized businesses that run their own mail servers. Zimbra shipped a fix in November 2025. Attacks began in July 2025 or earlier, according to the joint advisory from CISA and its partners.
What does the attack actually do?
It reads your inbox for you, without you ever clicking anything. The malicious code sits inside an email, and it runs the instant the victim opens that email in a vulnerable Zimbra webmail tab.
That is unusual. Most phishing, which is when criminals send fake emails to trick staff into handing over passwords or opening booby-trapped files, needs the target to click a link or open an attachment. This one does not. Security researchers call this a view-based exploit. In plain terms: looking at the email is enough.
Once it runs, the code quietly copies the victim's last 90 days of email, the organisation's internal address book (called the Global Address List), and other account data, then ships it back to servers the hackers control. It also tries to plant ways to get back in later, so the intrusion survives a password reset.
Who is behind it, and what do they want?
The authoring agencies, led by NSA, FBI, CISA and the Dutch AIVD and MIVD, say LAUNDRY BEAR works on behalf of the Russian Federation and is focused on stealing email for intelligence purposes. Earlier campaigns, first flagged by AIVD and Microsoft in May 2025, hit Microsoft 365 accounts using stolen passwords bought on criminal markets and a fake European Defence and Security Summit sign-in page.
That earlier work was crude. Password spraying. Cookie theft. Adversary-in-the-middle phishing kits. The Zimbra campaign is a step up: a custom tool the group calls "Ulej" (Russian for beehive) paired with a real zero-day, meaning a software flaw the vendor did not know about when attacks started.
What versions are affected and what should defenders do?
Patch Zimbra now, hunt for signs the bug was already used against you, and rotate credentials for any account that logged into a vulnerable server. The CISA advisory ships indicator files in STIX format for threat hunters.
| Item | Detail |
|---|---|
| CVE | CVE-2025-66376 |
| Product | Zimbra Collaboration Suite webmail |
| Patched | November 2025 |
| Exploited since | At least July 2025 |
| Trigger | Viewing a malicious email |
| Data stolen | 90 days of email, GAL, session data |
Should ordinary users worry?
If your employer runs Zimbra and has not patched, assume email you sent or received in the past three months could have been read. Watch for password reset emails you did not request, unexpected login alerts, and suspicious replies to old email threads. Change your password from a device you trust, and turn on multi-factor authentication if it is not already on.
LAUNDRY BEAR is not going away. The advisory says the group will keep hunting for new email bugs and will fall back on social engineering, meaning manipulation of staff, when the technical route closes.



