Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Laundry Bear Campaign: A New Chapter in Cyber Espionage



US agencies have issued a warning about a sophisticated campaign by Russian group Laundry Bear that targets organizations using unpatched Zimbra Collaboration servers, utilizing a zero-day vulnerability to steal email accounts from unsuspecting victims.

  • US agencies have warned about a Russian group's campaign targeting unpatched Zimbra Collaboration servers.
  • The campaign, called "Laundry Bear," uses a zero-day vulnerability to steal email accounts from victims.
  • The attack starts with phishing emails that lead to a Base64 encoded payload in an SVG element.
  • The malware attempts to maintain access by harvesting credentials and exfiltrating data through HTTPS and DNS channels.
  • CISA recommends updating Zimbra deployments, reviewing published IOCs, and monitoring authentication activity for anomalies.
  • Mitigation strategies include implementing phishing-resistant multi-factor authentication and regular security audits.



  • US agencies have issued a warning about a sophisticated campaign by Russian group Laundry Bear, also known as Void Blizzard, that targets organizations using unpatched Zimbra Collaboration servers. The campaign, dubbed "Laundry Bear," utilizes a zero-day vulnerability, CVE-2025-66376, in the ZCS webmail service to steal email accounts from unsuspecting victims.


    According to the advisory published by the US Cybersecurity and Infrastructure Security Agency (CISA), Laundry Bear's attack starts with phishing emails sent from previously compromised accounts to evade detection and increase credibility. When victims open the message in Zimbra webmail, the embedded JavaScript executes through abused CSS @import directives, leading up to a Base64 encoded payload within an SVG element.


    This payload includes an XOR encrypted final script encoded in a Base64 inner payload, which launches a multi-stage script designed for reconnaissance, credential theft, and data collection. The malware attempts to maintain access by enabling IMAP, creating application passwords, harvesting two-factor authentication codes, and extracting saved browser password manager credentials.


    Collected data is exfiltrated through HTTPS and DNS channels to attacker-controlled infrastructure named Flowerbed, using a dedicated service called Catcher to receive and temporarily store stolen information. The campaign highlights the growing capability of smaller threat groups to exploit zero-days, bypass MFA protections, and compromise enterprise email environments for intelligence gathering and further attacks.


    CISA recommends that organizations running Zimbra update their deployments to the latest available versions, review published IOCs, and investigate possible connections to identified domains and IP addresses. Organizations should also monitor authentication activity for anomalies, revoke unauthorized application passcodes, particularly those created with the "ZimbraWeb" identifier, and check user accounts for unauthorized mailbox access.


    To mitigate this risk, organizations can implement phishing-resistant multi-factor authentication to reduce the risk of account compromise and limit the impact of similar campaigns. Additionally, regular security audits and vulnerability testing are crucial in preventing such attacks.




    Related Information:
  • https://www.ethicalhackingnews.com/articles/Laundry-Bear-Campaign-A-New-Chapter-in-Cyber-Espionage-ehn.shtml

  • https://securityaffairs.com/195901/apt/us-agencies-warn-of-laundry-bear-campaign-targeting-unpatched-zimbra-servers.html

  • https://nvd.nist.gov/vuln/detail/CVE-2025-66376

  • https://www.cvedetails.com/cve/CVE-2025-66376/


  • Published: Fri Jul 24 03:44:28 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us