DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // LAUNDRY-BEAR-TA488FIRST SEEN: JUL 2025

LAUNDRY BEAR (TA488)

ALSO KNOWN AS: Void Blizzard, CL-STA-1114, TA488, UNK_PitStop
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Russia (FSB-linked, first identified by Dutch AIVD/MIVD May 2025)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:JUL 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL80/100
RESOURCES88/100
PERSISTENCE88/100
STEALTH88/100
IMPACT80/100

CISA advisory AA26-204A (July 23, 2026) formally attributed a sustained Zimbra Collaboration Suite zero-day campaign to Laundry Bear, a Russia-state-supported actor first identified by Dutch intelligence in May 2025. The group exploited CVE-2025-66376, a 'half-click' or 'zero-click' XSS flaw in Zimbra webmail — meaning simply viewing a malicious email in a vulnerable client is enough to trigger credential and email theft, including up to 90 days of mail and 2FA bypass via IMAP application passcodes. The campaign ran from at least July 2025 through February 2026, targeting Ukrainian government agencies, US government bodies, NATO-member governments, and defense contractors before the group tore down infrastructure following public disclosure.

Cyber espionage targeting Western government, defense, and scientific organizations; email and credential harvesting across NATO member states

Zero-click/half-click Zimbra XSS exploit (CVE-2025-66376), tag-splitting HTML obfuscation to hide SVG onload payloads, Proton Mail and compromised accounts as lure senders, persistent mailbox access via IMAP application passcodes, credential harvesting, custom persistent malware implant deployment, infrastructure self-teardown on exposure

GOVERNMENT
DEFENSE
SCIENTIFIC RESEARCH
CRITICAL INFRASTRUCTURE
UKRAINE

Adversary-controlled Proton Mail accounts, compromised email addresses for lure delivery, Zimbra-targeting custom malware, rapidly torn-down C2 infrastructure post-disclosure

FILE DATE: JUL 2025
Operation GhostMail – Zimbra Zero-Day NATO Espionage
Multi-month half-click Zimbra zero-day campaign targeting NATO government webmail servers, Ukrainian agencies, and US defense orgs; exfiltrated up to 90 days of email per victim and bypassed 2FA before infrastructure teardown in Feb 2026.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn