SUBJECT PROFILE
CISA advisory AA26-204A (July 23, 2026) formally attributed a sustained Zimbra Collaboration Suite zero-day campaign to Laundry Bear, a Russia-state-supported actor first identified by Dutch intelligence in May 2025. The group exploited CVE-2025-66376, a 'half-click' or 'zero-click' XSS flaw in Zimbra webmail — meaning simply viewing a malicious email in a vulnerable client is enough to trigger credential and email theft, including up to 90 days of mail and 2FA bypass via IMAP application passcodes. The campaign ran from at least July 2025 through February 2026, targeting Ukrainian government agencies, US government bodies, NATO-member governments, and defense contractors before the group tore down infrastructure following public disclosure.
Cyber espionage targeting Western government, defense, and scientific organizations; email and credential harvesting across NATO member states
OPERATIONAL HISTORY
Zero-click/half-click Zimbra XSS exploit (CVE-2025-66376), tag-splitting HTML obfuscation to hide SVG onload payloads, Proton Mail and compromised accounts as lure senders, persistent mailbox access via IMAP application passcodes, credential harvesting, custom persistent malware implant deployment, infrastructure self-teardown on exposure
KNOWN INFRASTRUCTURE
Adversary-controlled Proton Mail accounts, compromised email addresses for lure delivery, Zimbra-targeting custom malware, rapidly torn-down C2 infrastructure post-disclosure