---
schema: 1
kind: threat
title: >
  Russian state actor LAUNDRY BEAR weaponised a Zimbra webmail zero-click (CVE-2025-66376) for
  mailbox exfiltration — now exposed in a 16-nation joint advisory
headline: >
  16-nation advisory: Russia's LAUNDRY BEAR exfiltrates government mail through a view-based
  Zimbra exploit, and patching alone does not evict it
summary: >
  A joint Cybersecurity Advisory (AA26-204A) co-sealed by security and intelligence agencies from
  16 US, NATO and EU-member nations attributes a sustained email-espionage campaign against Zimbra
  Collaboration Suite to the Russian state actor LAUNDRY BEAR (Void Blizzard / CL-STA-1114 /
  TA488). Since July 2025 it has abused CVE-2025-66376 — a stored XSS in the ZCS Classic Web
  Client that runs on merely viewing a crafted email — to steal 90 days of mail, the Global
  Address List and 2FA codes, and to mint an IMAP application passcode that survives the patch and
  any password reset.
discovered_at: "2026-07-24T04:36:09Z"
updated_at: "2026-07-25T04:38:26Z"
event_date: 2026-07-23
run_id: 2026-07-24T0409Z-intel
priority: high
immediate_action: null
tags:
  - nation-state
  - espionage
  - actively-exploited
  - zero-click
  - cisa-kev
  - identity
  - ai-abuse
  - russia-nexus
  - phishing
regions:
  - global
  - europe
sectors:
  - public-sector
  - energy
  - defense
  - education
  - telco
entities:
  - "actor:laundry-bear"
  - "tool:ulej-flowerbed"
techniques:
  - T1566
  - T1203
  - T1059.007
  - T1027.017
  - T1114.002
  - T1087.003
  - T1556.006
  - T1539
  - T1048.003
  - T1608
  - T1098
  - T1071.004
affected_products:
  - Zimbra Collaboration Suite (Classic Web Client)
  - Zimbra Collaboration Suite
cves:
  - id: CVE-2025-66376
    cvss: 7.2 (MITRE CNA) / 6.1 (NVD)
    epss: "0.1201"
    type: xss
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
    affected: "ZCS 10.0.x < 10.0.18; 10.1.x < 10.1.13"
    fixed: 10.0.18 / 10.1.13
sources:
  - url: "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a"
    publisher: CISA / NSA / FBI + allied agencies from 16 nations (joint CSA AA26-204A)
    date: 2026-07-23
    role: primary
  - url: "https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign"
    publisher: NCSC-UK
    date: 2026-07-23
    role: primary
  - url: "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
    publisher: Palo Alto Networks Unit 42
    date: 2026-07-23
    role: corroborating
  - url: "https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits"
    publisher: Proofpoint
    date: 2026-07-23
    role: corroborating
  - url: "https://therecord.media/zimbra-webmail-zero-click-phishing-russia-laundry-bear"
    publisher: The Record (Recorded Future News)
    date: 2026-07-23
    role: corroborating
closed_sources: []
evidence:
  - quote: "Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR's latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service."
    publisher: CISA / NSA / FBI + allied agencies from 16 nations (joint CSA AA26-204A)
  - quote: A patch for CVE-2025-66376 was released for both 10.1.13 and 10.0.18 versions of ZCS.
    publisher: CISA / NSA / FBI + allied agencies from 16 nations (joint CSA AA26-204A)
  - quote: Threat actors continue to actively target unpatched ZCS instances using CVE-2025-66376.
    publisher: Palo Alto Networks Unit 42
  - quote: "the sanitizer fails to recognize it as executable markup, while the browser successfully reconstructs `<svg onload=\"eval(atob('…'))\">` and executes it."
    publisher: Proofpoint Threat Research
  - quote: "Proofpoint has not observed TA458 using CVE-2025-66376, despite the group's regular access to webmail XSS zero-days."
    publisher: Proofpoint Threat Research
verification: multi-source
sourcing_note: >
  Exploit framing differs by source: CISA describes it precisely as 'view-based' (executes when
  the message is rendered in the vulnerable Classic Web Client); NCSC-UK and Unit 42 use the
  industry shorthand 'zero-click' for the same mechanism, which preview-pane rendering makes
  effectively no-interaction — recorded here as zero-click with the CISA nuance stated in the
  body. CVSS is split across scorers (MITRE/CNA 7.2, NVD 6.1, ENISA EUVD mirrors 7.2); the
  discrepancy turns on UI:N vs UI:R, and is why single-source CVSS understates a flaw two separate
  Russian actors chose to weaponise.
confidence: high
references:
  - 2026-07-25/ta458-roundpress-webmail-zero-days-sogo-cve-2026-8496
deep_dive: true
deep_dive_category: apt-campaign
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - Confirm every on-prem Zimbra Collaboration Suite instance is on ZCS ≥ 10.0.18 or ≥ 10.1.13 specifically for CVE-2025-66376 — this is a distinct patch from the ZCS 10.1.19 and 10.1.20 fixes tracked earlier this month.
  - "On any ZCS account suspected of exposure, revoke all application-specific passwords and regenerate 2FA scratch codes, then disable IMAP where it is not required — patching stops the next crafted email but does not revoke access an earlier one already established."
  - "On any Zimbra account touched by the CVE-2025-66376 campaign, revoke application-specific passwords via the admin console — not just reset the user password: the attacker-created 'ZimbraWeb' app-password survives a password reset and the patch and grants standalone IMAP/POP3/SMTP mailbox access."
updates:
  - at: "2026-07-25T04:38:26Z"
    run_id: 2026-07-25T0409Z-intel
    type: update
    summary: >
      Proofpoint's writeup of the LAUNDRY BEAR (TA488/Void Blizzard) Zimbra CVE-2025-66376 campaign
      adds the technical mechanics the 16-nation joint advisory did not spell out: the CSS-@import
      sanitizer-bypass-by- reassembly that reconstructs an executing <svg onload=eval(atob(...))>,
      DNS-tunnelled exfiltration, and a persistent "ZimbraWeb" application-specific password created
      via the SOAP API that survives both a user password reset and the CVE-2025-66376 patch.
    fields:
      - actions
      - affected_products
      - evidence
      - references
      - tags
      - techniques
      - body
    merged_from: 2026-07-25/laundry-bear-zimreaper-app-password-persistence
  - at: "2026-09-06T13:50:00Z"
    run_id: 2026-09-06T1308Z-audit
    type: correction
    internal: true
    summary: >
      The recorded EPSS carried a percent sign and the percentage figure ("12.01%"), not the
      probability the field holds. Converted to 0.1201, the same value expressed as the FIRST.org
      probability. No reader-facing statement changes; the units are now stated normatively in the
      data model.
    fields: [cves]
migrated_from: null
---

**Background.** LAUNDRY BEAR — named by the Netherlands' AIVD/MIVD in May 2025, tracked as Void Blizzard by Microsoft, CL-STA-1114 by Unit 42 and TA488 (formerly UNK_PitStop) by Proofpoint — is a Russian state-supported espionage actor that, until this campaign, relied on password spraying, adversary-in-the-middle credential phishing (a modified Evilginx) and pass-the-cookie against Microsoft Exchange and cloud mail ([CISA, 2026-07-23](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a)). The 2026-07-23 joint advisory AA26-204A, co-sealed by security and intelligence agencies from sixteen US, Five Eyes and EU-member nations including ANSSI/DGSI (France), AISE/AISI (Italy), AIVD/MIVD (Netherlands) and NCSC-UK, documents its shift to a genuinely technical exploit and assesses the covert, non-extortion nature of the activity as "almost certainly" Russian-government-backed espionage ([CISA, 2026-07-23](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a)).

Since at least July 2025 the actor has exploited **CVE-2025-66376**, a stored cross-site-scripting flaw in the Zimbra Collaboration Suite (ZCS) Classic Web Client caused by improper sanitisation of CSS `@import` directives in HTML email ([Unit 42, 2026-07-23](https://unit42.paloaltonetworks.com/russian-webmail-espionage/)). A crafted message smuggles a Base64-encoded, XOR-obfuscated JavaScript payload inside an SVG element's `onload` attribute; the script executes inside the victim's authenticated webmail session the moment the message is rendered. CISA describes this precisely as **view-based** — it "only requires a user to view a malicious email within a vulnerable version of the webmail service" ([CISA, 2026-07-23](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a)) — while NCSC-UK and Unit 42 call it zero-click; with preview-pane rendering the practical effect is the same, and there is no link to click or attachment to open. It was a true zero-day when first used, and Synacor did not patch it until ZCS 10.0.18 / 10.1.13 in November 2025 — yet Unit 42 confirms attackers "continue to actively target unpatched ZCS instances" today ([Unit 42, 2026-07-23](https://unit42.paloaltonetworks.com/russian-webmail-espionage/)). This is a third, distinct ZCS Classic Web Client flaw from the two unrelated July 2026 issues this store already tracks (the no-CVE code-exec fixed in 10.1.19 and the SNMP command-injection RCE fixed in 10.1.20).

**Kill chain.** On render, the payload ("Ulej", Russian for beehive) pulls the session CSRF token from browser `localStorage` and drives a 12-stage asynchronous collection routine over the Zimbra SOAP API: it retrieves the victim's last ~90 days of mail, brute-forces the organisation's **Global Address List** through repeated two-character `SearchGalRequest` batches (roughly twenty batches of ~77 queries), harvests `GetScratchCodesRequest` 2FA backup codes, and — the persistence pivot — issues `CreateAppSpecificPasswordRequest` to mint an IMAP application passcode (observed named `ZimbraWeb`) that bypasses ZCS's lack of native 2FA on IMAP, then flips `zimbraPrefImapEnabled` to true ([CISA, 2026-07-23](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a)). Because that application passcode is a legitimate credential, it survives both the November patch and any subsequent password reset — as The Hacker News put it in its analysis, patching "stops the next crafted email from running. It does not revoke what the last one left behind" ([The Hacker News, 2026-07-23](https://thehackernews.com/2026/07/russian-espionage-group-exploited.html)). Exfiltration runs over both Base32-encoded DNS A-record queries and HTTPS to a Dockerised "Flowerbed" collection stack (Catcher/Certbot/Nginx/Gardener containers, Let's Encrypt via Cloudflare DNS challenge) on short-lived VPS infrastructure reached over Mullvad VPN; CISA notes the simplistic Flowerbed codebase shows indications of AI-assisted development. Since ~November 2025 the actor has also sent lures from already-compromised victim mailboxes, defeating sender-reputation filtering ([CISA, 2026-07-23](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a)). Targeting spans the Defence Industrial Base, federal and local government, education, energy, law enforcement, media and NGOs across NATO states, with Ukraine used as an earlier testbed ([NCSC-UK, 2026-07-23](https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign)).

**Defender takeaway:** Any Swiss or European public-sector, energy or education body running on-prem Zimbra Classic Web Client should treat this as two separate jobs. First, confirm the instance is on ZCS ≥ 10.0.18 / ≥ 10.1.13 — the specific fix for this CVE, independent of the other two July patch cycles — and, where patching lags, move users off the Classic Web Client (the Modern client and IMAP/desktop clients are not exposed to this XSS vector). Second, hunt for and evict established persistence, because the patch does not: in `/opt/zimbra/log/mailbox.log` (or `audit.log`) look for bursts of `SearchGalRequest` SOAP calls from a single user in a short window, any `CreateAppSpecificPasswordRequest` or `GetScratchCodesRequest` outside expected admin workflows, and `ModifyPrefsRequest` toggling `zimbraPrefImapEnabled`; in the browser origin, an `zd_comp_YYYY-MM-DD`-keyed `localStorage` marker is the actor's own de-duplication artifact and persists post-compromise. **Triage:** application-specific passwords and IMAP-enable events are legitimate admin actions in many estates — the discriminators are an app passcode created by an end-user session rather than an admin, a name like `ZimbraWeb` with no operational reason to exist, and its co-occurrence with GAL-enumeration bursts and long high-entropy DNS lookups to non-organisational VPS resolvers; any one alone is weak, the sequence is the signal. Treat a newly created ZCS application passcode as a persistence indicator requiring revocation, not merely a password reset.

## Update — 2026-07-25T04:38:26Z

The prior entry covered the 16-nation joint advisory (AA26-204A) on LAUNDRY BEAR's (TA488 / Void Blizzard) zero-click Zimbra campaign exploiting CVE-2025-66376. Proofpoint's own two-part writeup adds mechanics the advisory did not detail ([Proofpoint, 2026-07-23](https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits)).

The exploit defeats Zimbra's client-side HTML sanitizer by tag-splitting: a fake CSS `@import` directive is fragmented across HTML tags so that the sanitizer strips each `@import` sequence individually, but "the browser successfully reconstructs `<svg onload="eval(atob('…'))">` and executes it" — a sanitizer-bypass-by-reassembly, where the surviving characters rejoin into valid executing script ([Proofpoint, 2026-07-23](https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits)). The resulting payload — which Proofpoint attributes to LAUNDRY BEAR's post-exploitation tooling and names ZimReaper — steals CSRF tokens, browser-autofill credentials, 2FA scratch codes and the Zimbra version/URL, exfiltrating tokens via DNS tunneling (Base32-encoded subdomains carrying a session id and a plaintext token-type label) and mail archives via HTTP POST.

The operationally important delta is persistence: after exploitation ZimReaper issues a `CreateAppSpecificPasswordRequest` to mint a Zimbra application-specific password labelled "ZimbraWeb" that bypasses 2FA and grants IMAP/POP3/SMTP access, then exfiltrates it via DNS for direct mailbox access ([Proofpoint, 2026-07-23](https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits)). Because that credential is independent of the primary account password, it survives a password reset and the CVE-2025-66376 patch alike. **Defender takeaway:** anyone who responded to the original advisory by patching and forcing password resets has not necessarily evicted the attacker — the app-specific password must be enumerated and revoked separately. Proofpoint also assesses that the sibling GRU actor TA458 (see references) was *not* observed using CVE-2025-66376 despite its own webmail zero-day access, suggesting the exploit was allocated to TA488 by "upstream Russian intelligence taskmasters" and deconflicted between the two clusters; Proofpoint has seen no TA488 activity since February 2026. **Triage:** hunt for a Zimbra SOAP/REST call creating a new application-specific password shortly after an anomalous webmail message-render event on the same account — benign app-password provisioning is user-initiated from account settings, not API-driven immediately after a message open; anomalous DNS query volume/entropy from the mail-server host is a second, independent hook for the exfiltration channel.
