Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Claude Cowork Sandbox Escape Flaw Exposes SSH Keys, Cloud Credentials
July 24, 2026
Microsoft detects 7.6B email phishing threats, Teams vishing up 10x
July 24, 2026
Russian Hackers Exploit Critical Zimbra Zero-Day to Steal Emails
July 24, 2026
Home/CyberSecurity News/Russian Hackers Exploit Critical Zimbra Zero-Day to Steal Emails
CyberSecurity News

Russian Hackers Exploit Critical Zimbra Zero-Day to Steal Emails

Key Takeaways A Russian state-sponsored hacking group, LAUNDRY BEAR, is actively exploiting a zero-day vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite (ZCS). The attacks leverage a...

Sarah simpson
Sarah simpson
July 24, 2026 3 Min Read
2 0

Key Takeaways

  • A Russian state-sponsored hacking group, LAUNDRY BEAR, is actively exploiting a zero-day vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite (ZCS).
  • The attacks leverage a cross-site scripting (XSS) flaw to steal sensitive information, including emails, from targeted organizations.
  • Targets include Western government, defense, energy, education, media, NGO, and technology sectors, with a focus on espionage.
  • The exploit is triggered by simply viewing a specially crafted spear-phishing email; no user interaction is required.
  • Organizations must urgently patch ZCS and revoke all Zimbra Application Passcodes and 2FA scratch codes.

Russian Hackers Exploit Zimbra Zero-Day for Espionage

A sophisticated cyberespionage campaign attributed to the Russian state-sponsored hacking collective known as LAUNDRY BEAR is currently leveraging a zero-day vulnerability within the Zimbra Collaboration Suite (ZCS). The threat actors are exploiting this critical flaw to surreptitiously extract sensitive data, primarily emails, from high-value Western targets.

Table Of Content

  • Key Takeaways
  • Russian Hackers Exploit Zimbra Zero-Day for Espionage
  • The “Ulej” Framework and Initial Compromise
  • Data Exfiltration via “Flowerbed”
  • What You Should Do

This operation diverges from typical financially motivated cybercrime, focusing instead on intelligence gathering. Affected sectors span government, defense, energy, education, media, non-governmental organizations (NGOs), and technology.

The “Ulej” Framework and Initial Compromise

The core of the attack exploits CVE-2025-66376, a cross-site scripting (XSS) vulnerability found in ZCS webmail. LAUNDRY BEAR employs a unique capability dubbed “Ulej,” meaning “beehive” in Russian, to orchestrate their malicious activities.

The initial compromise begins with a spear-phishing email that contains a malicious JavaScript payload embedded within an SVG image. Crucially, this exploit requires no user interaction beyond simply viewing the email in a vulnerable Zimbra client. The flaw’s improper handling of CSS triggers the code execution automatically.

Upon execution, the JavaScript initiates an automated sequence to harvest vital information from the victim’s account. This includes the user’s email address, device status, details on OAuth consumers, and even two-factor authentication (2FA) scratch codes.

The script then programmatically enables IMAP access and generates a new Zimbra Application Passcode, specifically named “ZimbraWeb.” This newly created passcode grants the attackers persistent access, effectively bypassing ZCS’s native 2FA protections. Furthermore, the malicious payload attempts to manipulate password managers, prompting them to autofill credentials into hidden login forms, which facilitates additional credential theft.

Data Exfiltration via “Flowerbed”

For email exfiltration, the script systematically queries the victim’s mailbox for non-junk messages sent within the last 90 days. The collected data is then compressed and prepared for transfer through the Ulej framework to attacker-controlled servers. These servers host a Python-based collection system known as “Flowerbed.”

The Flowerbed system is designed to prevent redundant collection of emails that have already been exfiltrated. However, emails from the current day are consistently collected with each subsequent execution of the exploit.

Data exfiltration leverages both HTTPS and DNS as covert transmission channels. Smaller data packets are encoded in Base32 and transmitted via DNS lookups triggered by specially crafted image URLs. Larger files, such as email archives and Global Address List (GAL) contents, are transferred over HTTPS to the Flowerbed infrastructure, which is secured by Let’s Encrypt certificates and fronted by an Nginx reverse proxy.

The Flowerbed setup utilizes Docker containers for various operational tasks, including HTTP/DNS exfiltration and health checks. It also employs VPN services like Mullvad to obfuscate its activities. JSON logs and payload files are carefully staged for exfiltration, with older files automatically purged to maintain operational stealth.

According to CISA Advisory AA26-204A, there is evidence suggesting that AI tools were used in the development of the Flowerbed codebase. This highlights an emerging trend of threat actors leveraging artificial intelligence to accelerate and enhance offensive cyber operations.

Despite the stealthy nature of this campaign, defenders have several opportunities for detection. For instance, ZCS mailbox logs may exhibit unusual SOAP activity, signaling a potential compromise. Additionally, entries in browser localStorage can reveal specific email exfiltration dates, which can be invaluable during incident response efforts.

What You Should Do

  • Patch Immediately: Organizations are urged to urgently apply patches for the CVE-2025-66376 vulnerability in Zimbra Collaboration Suite.
  • Revoke Passcodes: Revoke all existing Zimbra Application Passcodes, especially any named “ZimbraWeb,” and all two-factor authentication scratch codes.
  • Monitor Logs: Actively monitor ZCS mailbox logs for unusual SOAP activity and other indicators of compromise.
  • Alternative Access: Consider implementing alternative, more secure methods for email access to mitigate risks from such stealthy attacks.
  • User Awareness: Educate users about spear-phishing tactics and the dangers of viewing suspicious emails, even without clicking links or attachments.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitHackerMalwarePatchphishingThreatVulnerabilityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Decathlon Investigates Alleged Breach of 160 Million Customer Records

Next Post

Microsoft detects 7.6B email phishing threats, Teams vishing up 10x

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Notepad++ Plugin Vulnerability Lets Attackers Compromise Systems
July 23, 2026
Chaos Ransomware Exploits Chrome and Edge to Create Covert Command Channel
July 23, 2026
OPSEC Error Uncovers TriBack Malware in Global Espionage Campaign
July 23, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us