Australia’s Signals Directorate has joined fifteen other national cyber agencies in warning that a Russian state backed hacking group is running an ongoing zero click phishing campaign against organisations that run Zimbra Collaboration Suite webmail, according to the UK’s National Cyber Security Centre. The group, tracked as Laundry Bear, has been quietly harvesting up to ninety days of email, saved passwords and authentication tokens from victims who never clicked a link or opened an attachment, they only had to preview a message. “This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology,” said NCSC Chief Operating Officer Beth Hopkins CMG.
How does the exploit compromise a mailbox without a click?
The campaign exploits CVE-2025-66376, a stored cross site scripting flaw in Zimbra’s Classic web interface, according to The Hacker News. Attackers hide malicious HTML inside an email sent from a previously compromised account, splitting an image tag’s onload instruction across several hidden divisions so that Zimbra’s sanitiser never recognises the fragments as a single executable block. Once the message renders in the inbox preview pane, the script fires on its own, no click, no download, no attachment needed.
NCSC and its partners refer to the payload as beehive, the same capability Dutch investigators who first named Laundry Bear translate as Ulej, Russian for beehive, according to CyberScoop. Once triggered, it pulls the victim’s most recent ninety days of mail, the organisation’s full address book, saved browser passwords, two factor authentication recovery codes and active session tokens, all without a second email or any further action from the victim. Zimbra patched the underlying flaw in versions 10.0.18 and 10.1.13, according to The Hacker News, but the joint advisory says exploitation had already been running since July 2025, well before the fix shipped.
Who is Laundry Bear, and what does Russia want with mailboxes?
Laundry Bear is also tracked under the names Void Blizzard, CL STA 1114 and TA488, and investigators assess with high confidence that it operates with Russian government backing, according to The Record. The advisory notes the group has shown no interest in ransom demands or financial extortion, a pattern the co-signing agencies say points toward espionage rather than ordinary cybercrime. Targets span government agencies, the defence industrial base, energy operators, law enforcement, media organisations, universities and technology companies across NATO member states, Ukraine, former Soviet states and parts of Africa, according to CyberScoop.
| What happened | Sixteen national cyber agencies, including Australia’s ASD, warned of an ongoing zero click phishing campaign against Zimbra webmail users run by the Russian state backed group Laundry Bear |
|---|---|
| When | Active since July 2025, according to the NCSC; the joint advisory was published on 22 to 23 July 2026 |
| Who is affected | Government, defence, energy, law enforcement, media, education, technology and financial organisations running Zimbra Collaboration Suite across NATO states, Ukraine, former Soviet states and Africa, according to CyberScoop |
| Scale | Up to ninety days of email, saved passwords and authentication tokens exposed per compromised mailbox, with no user click required |
| Fix or deadline | Patch to Zimbra 10.0.18, 10.1.13 or later immediately; reset passwords and two factor tokens for any account that opened a suspicious message |
Why should CISOs who do not run Zimbra still pay attention?
The advisory is a reminder that the assumption underlying most phishing defences, that a user has to click something, no longer holds. It sits alongside the lesson boards drew from APT28’s exploitation of a Microsoft Office zero day against European targets earlier this year: state backed groups are increasingly weaponising the productivity software every organisation already trusts, not just the links inside it. Programmes built around teaching staff to spot suspicious links, of the kind laid out in our security awareness training versus human risk management guide, still matter, but they cannot catch an exploit that never asks the user to do anything at all.
The bigger governance issue is patch latency on internet facing collaboration platforms. Zimbra shipped a fix months before this advisory went public, yet sixteen national agencies still felt the need to warn their critical infrastructure operators that exploitation was ongoing. That is the same gap CISA has been trying to close with binding directives, most recently ordering federal agencies to patch a maximum severity Adobe ColdFusion flaw, and it echoes the urgency behind this month’s Ivanti Sentry advisory for a pre-auth root flaw. Boards asking about resilience should be asking how long an exploited but unpatched internet facing service sits in their environment, not only whether phishing awareness training happened this quarter.
What should security teams do this week?
The joint advisory, co-signed by agencies in Australia, the UK, the US, Canada, New Zealand and eleven European countries, lays out a short list of actions for any organisation running Zimbra Collaboration Suite:
- Patch to Zimbra 10.0.18, 10.1.13 or later immediately, or move affected users to an alternative mail client if patching is not immediately possible, according to The Record.
- Reset passwords and invalidate active sessions for any account that opened a suspicious message, and force re-enrollment of two factor authentication.
- Review audit logs for unexpected CreateAppSpecificPassword calls, unusual IMAP enablement and DNS based exfiltration patterns, according to The Hacker News.
- Fold internet facing webmail and collaboration platforms into the same monthly patch cadence used for cycles like Microsoft’s July Patch Tuesday, rather than treating them as lower priority systems.
None of the sixteen agencies involved have said the campaign has stopped. Until every Zimbra deployment is confirmed patched, the safest working assumption for any CISO running the platform is that Laundry Bear has already read what it wanted to.
Frequently asked questions
What is the Laundry Bear Zimbra phishing campaign?
It is an ongoing zero click phishing campaign run by the Russian state backed group Laundry Bear, also tracked as Void Blizzard, that exploits a stored cross site scripting flaw in Zimbra Collaboration Suite webmail. Victims are compromised simply by viewing a malicious email, with no link or attachment required, according to the UK’s National Cyber Security Centre.
Did Australia’s ASD confirm involvement in the advisory?
Yes. Australia’s Signals Directorate joined fifteen other national cyber agencies, including the UK’s NCSC, the US CISA and NSA, and agencies across Canada, New Zealand and Europe, in co-signing the joint advisory that warned organisations running Zimbra Collaboration Suite about the ongoing campaign.
What should organisations running Zimbra do right now?
Security agencies urge immediate patching to Zimbra versions 10.0.18 or 10.1.13 or later, resetting passwords and two factor authentication for any account that opened a suspicious message, and reviewing audit logs for unusual IMAP activity or unexpected app specific password creation, according to the joint advisory.

Leave a Reply