Russian APT Laundry Bear Exploits Zimbra Zero-Day in Global Espionage Campaign
Key Questions
Who is the Laundry Bear threat actor and what did it target?
Laundry Bear, also known as Void Blizzard, is a Russian state-sponsored group that exploited a Zimbra zero-day since July 2025 against Western government, defense, energy, and tech sectors. It used 'beehive' capabilities to exfiltrate 90 days of emails and address lists.
What vulnerability did Laundry Bear exploit and how was it disclosed?
The group exploited CVE-2025-66376, a zero-click Zimbra vulnerability, in a global espionage campaign first tested on Ukraine. A joint CISA/NSA/FBI advisory with multi-nation partners confirmed the activity.
What was the scope of the Laundry Bear campaign?
It compromised organizations across Western countries, including US nuclear scientists and defense contractors, stealing sensitive data over five months before patching. Advisories highlight persistent targeting of government and commercial entities.
How long did the Zimbra exploit go undetected?
Laundry Bear used the zero-day for five months prior to patching, enabling widespread email exfiltration in espionage operations.
What sectors were primarily impacted by Laundry Bear?
Targets focused on Western governments, defense, energy, and technology organizations, with specific warnings about nuclear scientists and contractors.
What mitigation is recommended for the Zimbra vulnerability?
The advisory emphasizes immediate patching despite medium CVSS rating and improved patch hygiene for email collaboration platforms like Zimbra.
Is Laundry Bear activity ongoing?
Yes, the campaign has been active since July 2025 with global deployment after Ukraine testing, underscoring ongoing nation-state email espionage risks.
How does this relate to broader Russian cyber operations?
It aligns with persistent Russian state-backed efforts targeting Western entities for intelligence, as detailed in Unit 42 and CISA reports on similar webmail espionage.
Joint CISA/NSA/FBI advisory confirms Russian state-sponsored actor Laundry Bear (Void Blizzard) exploiting CVE-2025-66376, a zero-click Zimbra vulnerability, since July 2025. Targets Western government, defense, energy, and tech sectors. Uses 'beehive' capability to exfiltrate 90 days of email and global address lists. Testing on Ukraine before global deployment. Multi-nation advisory underscores high confidence. This reinforces nation-state email targeting and the need for patch hygiene despite medium CVSS. Not a market mover but essential situational awareness for affected sectors.