DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // LAUNDRY-BEARFIRST SEEN: JUL 2025

LAUNDRY BEAR

ALSO KNOWN AS: Void Blizzard, CL-STA-1114, TA488
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Russia (Russian Federation state-sponsored)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:JUL 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL78/100
RESOURCES86/100
PERSISTENCE86/100
STEALTH86/100
IMPACT78/100

Russian state-sponsored APT group named by the Netherlands AIVD/MIVD, publicly attributed in a major joint CISA/NSA/FBI advisory (AA26-204A) on July 23, 2026. The group exploited CVE-2025-66376, a stored XSS zero-day in Zimbra Collaboration Suite's Classic UI, deploying a custom capability called 'Ulej' (Russian: beehive) to silently exfiltrate email, 2FA tokens, and app-specific passwords — requiring only that a victim view a malicious email to trigger exploitation. A notable OPSEC trait is the use of Mullvad VPN services to obscure origin, and the advisory noted possible AI-assisted development in Ulej's codebase.

Cyber espionage; covert acquisition of email data from Western government and commercial targets on behalf of the Russian Federation

Zero-day exploitation (CVE-2025-66376 Zimbra XSS), view-based exploit delivery (no user click required), custom exfiltration tool 'Ulej', 2FA token harvesting, app-specific password minting, IMAP persistence implant, password spraying, adversary-in-the-middle phishing, session-token replay, Mullvad VPN abuse for operational cover

GOVERNMENT
DEFENSE-INDUSTRIAL-BASE
ENERGY
LAW-ENFORCEMENT
EDUCATION
MEDIA
TECHNOLOGY
NGOS

Websites impersonating legitimate services (per CISA IOCs), Mullvad VPN exit nodes, custom 'Ulej' data exfiltration capability, SOAP API abuse for Zimbra enumeration (GetInfoRequest, GetScratchCodesRequest, GetDeviceStatusRequest, GetOAuthConsumersRequest)

FILE DATE: JUL 2025
Operation Ulej / Zimbra ZCS Campaign
Ongoing campaign exploiting Zimbra CVE-2025-66376 as a zero-day against 10+ Western government, DIB, energy, law enforcement, media, and NGO organizations; publicly disclosed via joint CISA advisory AA26-204A on July 23, 2026.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn