Russian State Hackers Exploiting Patched Zimbra Flaw to Steal Email
CISA has issued an urgent advisory warning that Laundry Bear (also tracked as Void Blizzard), a Russian state-sponsored threat actor, is actively combining phishing campaigns with exploitation of a now-patched zero-click vulnerability in Zimbra Collaboration to steal email from targeted organizations.
What Happened
According to BleepingComputer's reporting, Laundry Bear has developed a two-stage attack chain: phishing emails provide initial access, which is then combined with exploitation of a Zimbra vulnerability to achieve silent email exfiltration — no further user interaction required after that first foothold. CISA's advisory flags this as an ongoing, active campaign against organizations running unpatched Zimbra Collaboration servers.
Laundry Bear has previously been linked to espionage campaigns targeting NATO-aligned governments and defense-adjacent organizations. This campaign continues that pattern, with bulk email content representing high-value intelligence for a state actor.
Why This Matters
The attack chain is dangerous for two compounding reasons. First, the zero-click exploitation component means that once an attacker gains a foothold — even via a single phished credential — they can silently vacuum email archives without any additional user action. No malicious attachment needs to be opened, no link clicked a second time. Second, Zimbra is widely deployed in enterprise and government environments as an on-premises alternative to Exchange or Google Workspace, making the attack surface broad and the targets plentiful.
If your organization runs Zimbra on-premises and hasn't applied recent security patches, you are likely still exposed to the flaw being weaponized right now. A fix exists — the risk is entirely in deployment lag. This is also a reminder that phishing is still the front door: a fully patched Zimbra instance remains vulnerable to the credential-theft stage of this chain.
What To Do
Patch immediately. Apply all available Zimbra Collaboration security updates. Check your installed version against Zimbra's official security advisories and treat any patch addressing remote code execution or mail-access vulnerabilities from 2024–2025 as critical.
Pull the CISA IOCs. The advisory includes indicators of compromise and detection signatures specific to Laundry Bear's tooling. Ingest those IOCs into your SIEM and run retrospective searches across mail server logs now — not after your next scheduled review cycle.
Audit mail server access logs. Look for anomalous IMAP or API access patterns: bulk export behavior, connections from unexpected IP ranges, or high-volume read activity on accounts that don't normally generate it. Laundry Bear operations consistently involve large-scale email collection.
Harden phishing defenses. Since the chain starts with phishing, enforce MFA on all Zimbra accounts, verify DMARC enforcement is active on your sending domains, and confirm your mail gateway is flagging externally-originating spoofed messages.
Isolate if you cannot patch. If an immediate update is operationally impossible, restrict external access to Zimbra's webmail and API interfaces until the patch window opens.
State-sponsored email theft differs meaningfully from opportunistic ransomware: these actors are patient, selective, and specifically interested in what your organization has been communicating. This is a patch-or-isolate situation — not a next-cycle item.
Synthesized by Claude · sanity-checked before publish.