Vulnerabilities

CVE-2025-66376: Zimbra Email Theft via Zero-Click Flaw

July 23, 2026 20:03 · 10 min read
CVE-2025-66376: Zimbra Email Theft via Zero-Click Flaw

Russian Hackers Exploit Zimbra Zero-Click Flaw for Email Theft

The Russian state-sponsored hacking group, Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers. According to CISA, the group combines phishing attacks with the exploitation of a now-patched Zimbra vulnerability, CVE-2025-66376, to steal email data.

Exploitation of Zimbra Vulnerability

The CVE-2025-66376 vulnerability is a cross-site scripting (XSS) flaw affecting Zimbra Collaboration Suite's Classic UI. It allows JavaScript embedded in specially crafted HTML emails to execute automatically when a victim views the message, enabling attackers to steal account data without requiring the user to click a link or visit a phishing site.

Laundry Bear exploited the flaw as a zero-day before Zimbra patched it in November 2025 and continues to target organizations running unpatched servers. The vulnerability was later tagged by CISA as actively exploited in attacks.

Attack Techniques

CISA says Laundry Bear's exploit is used to automatically collect and send the victim's last 90 days of emails, email address, password, Global Address List (GAL), and two-factor authentication (2FA) tokens. The attackers also create and send back a new Zimbra application passcode, which is used by legacy email clients like IMAP or ActiveSync that do not support the TOTP authentication flows.

Using a passcode allows the attackers to retain access to the email account while bypassing MFA. The malware exfiltrates stolen information over both DNS and HTTPS to an actor-controlled server running the group's 'Flowerbed' collection framework.

Phishing Attacks

In addition to exploiting the Zimbra flaw, Laundry Bear also utilizes adversary-in-the-middle (AiTM) phishing kits designed to impersonate legitimate Zimbra login portals, stealing credentials and session cookies, allowing the attackers to gain access to targets' email accounts.

CISA released IOCs that show the campaign used sites that impersonate Zimbra infrastructure, using domain names like 'mailnalysis.com', 'emailanalytics.com.ua', 'zimbrastat.com', 'zimbra-metadata.com', 'istc-cloud.com', and 'zmailanalytics.com'.

Recommendations

The advisory recommends that organizations using Zimbra: Update to the latest version of the software to install all available security updates. Review the published indicators of compromise. Investigate systems for connections to the identified domains and IP addresses. Monitor for suspicious authentication activity. Revoke any unauthorized application passcodes, especially those with the 'ZimbraWeb'. Review accounts for unauthorized mailbox access.

CISA also recommends implementing phishing-resistant multi-factor authentication where possible.

Laundry Bear Hacking Group

The Laundry Bear hacking group was first attributed to cyberespionage attacks in May 2025 by the Dutch intelligence agencies. The group has focused on intelligence collection against organizations aligned with Russian strategic interests, primarily targeting NATO member states and Ukraine.

Microsoft tracks the same group under the name Void Blizzard. Since at least 2024, the group has been involved in successful compromises of organizations supporting Ukraine, including entities in the defense, transportation, and aviation sectors.

Earlier this year, BleepingComputer reported on a separate Laundry Bear campaign targeting Ukraine's military using charity-themed phishing emails to deliver malware disguised as donation requests.

Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free