Russian Hackers Exploit Critical Zimbra Zero-Day to Steal Emails
Key Takeaways A Russian state-sponsored hacking group, LAUNDRY BEAR, is actively exploiting a zero-day vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite (ZCS). The attacks leverage a...
Key Takeaways
- A Russian state-sponsored hacking group, LAUNDRY BEAR, is actively exploiting a zero-day vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite (ZCS).
- The attacks leverage a cross-site scripting (XSS) flaw to steal sensitive information, including emails, from targeted organizations.
- Targets include Western government, defense, energy, education, media, NGO, and technology sectors, with a focus on espionage.
- The exploit is triggered by simply viewing a specially crafted spear-phishing email; no user interaction is required.
- Organizations must urgently patch ZCS and revoke all Zimbra Application Passcodes and 2FA scratch codes.
Russian Hackers Exploit Zimbra Zero-Day for Espionage
A sophisticated cyberespionage campaign attributed to the Russian state-sponsored hacking collective known as LAUNDRY BEAR is currently leveraging a zero-day vulnerability within the Zimbra Collaboration Suite (ZCS). The threat actors are exploiting this critical flaw to surreptitiously extract sensitive data, primarily emails, from high-value Western targets.
Table Of Content
This operation diverges from typical financially motivated cybercrime, focusing instead on intelligence gathering. Affected sectors span government, defense, energy, education, media, non-governmental organizations (NGOs), and technology.
The “Ulej” Framework and Initial Compromise
The core of the attack exploits CVE-2025-66376, a cross-site scripting (XSS) vulnerability found in ZCS webmail. LAUNDRY BEAR employs a unique capability dubbed “Ulej,” meaning “beehive” in Russian, to orchestrate their malicious activities.
The initial compromise begins with a spear-phishing email that contains a malicious JavaScript payload embedded within an SVG image. Crucially, this exploit requires no user interaction beyond simply viewing the email in a vulnerable Zimbra client. The flaw’s improper handling of CSS triggers the code execution automatically.
Upon execution, the JavaScript initiates an automated sequence to harvest vital information from the victim’s account. This includes the user’s email address, device status, details on OAuth consumers, and even two-factor authentication (2FA) scratch codes.
The script then programmatically enables IMAP access and generates a new Zimbra Application Passcode, specifically named “ZimbraWeb.” This newly created passcode grants the attackers persistent access, effectively bypassing ZCS’s native 2FA protections. Furthermore, the malicious payload attempts to manipulate password managers, prompting them to autofill credentials into hidden login forms, which facilitates additional credential theft.
Data Exfiltration via “Flowerbed”
For email exfiltration, the script systematically queries the victim’s mailbox for non-junk messages sent within the last 90 days. The collected data is then compressed and prepared for transfer through the Ulej framework to attacker-controlled servers. These servers host a Python-based collection system known as “Flowerbed.”
The Flowerbed system is designed to prevent redundant collection of emails that have already been exfiltrated. However, emails from the current day are consistently collected with each subsequent execution of the exploit.
Data exfiltration leverages both HTTPS and DNS as covert transmission channels. Smaller data packets are encoded in Base32 and transmitted via DNS lookups triggered by specially crafted image URLs. Larger files, such as email archives and Global Address List (GAL) contents, are transferred over HTTPS to the Flowerbed infrastructure, which is secured by Let’s Encrypt certificates and fronted by an Nginx reverse proxy.
The Flowerbed setup utilizes Docker containers for various operational tasks, including HTTP/DNS exfiltration and health checks. It also employs VPN services like Mullvad to obfuscate its activities. JSON logs and payload files are carefully staged for exfiltration, with older files automatically purged to maintain operational stealth.
According to CISA Advisory AA26-204A, there is evidence suggesting that AI tools were used in the development of the Flowerbed codebase. This highlights an emerging trend of threat actors leveraging artificial intelligence to accelerate and enhance offensive cyber operations.
Despite the stealthy nature of this campaign, defenders have several opportunities for detection. For instance, ZCS mailbox logs may exhibit unusual SOAP activity, signaling a potential compromise. Additionally, entries in browser localStorage can reveal specific email exfiltration dates, which can be invaluable during incident response efforts.
What You Should Do
- Patch Immediately: Organizations are urged to urgently apply patches for the CVE-2025-66376 vulnerability in Zimbra Collaboration Suite.
- Revoke Passcodes: Revoke all existing Zimbra Application Passcodes, especially any named “ZimbraWeb,” and all two-factor authentication scratch codes.
- Monitor Logs: Actively monitor ZCS mailbox logs for unusual SOAP activity and other indicators of compromise.
- Alternative Access: Consider implementing alternative, more secure methods for email access to mitigate risks from such stealthy attacks.
- User Awareness: Educate users about spear-phishing tactics and the dangers of viewing suspicious emails, even without clicking links or attachments.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.