Russian APT LAUNDRY BEAR Exploiting Zimbra Zero-Day CVE-2025-66376
Key Questions
What is the LAUNDRY BEAR APT group and what vulnerability are they exploiting?
LAUNDRY BEAR is a Russian state-sponsored advanced persistent threat actor targeting Zimbra Collaboration Suite with a view-based zero-day vulnerability tracked as CVE-2025-66376.
How does the Zimbra zero-day exploit work and what data does it steal?
The exploit activates simply by viewing a malicious email, allowing attackers to exfiltrate up to 90 days of mail along with the Global Address List from affected systems.
When was the Zimbra vulnerability patched and is exploitation ongoing?
The vulnerability was patched in November 2025, yet it remains actively exploited against U.S. and Ukrainian government and defense targets according to multi-agency alerts.
Which agencies have issued guidance on this threat?
CISA, NCSC, and other agencies have released a joint advisory including indicators of compromise to help organizations detect and respond to the campaign.
What actions should enterprise SOCs take regarding this Zimbra threat?
Organizations must apply the Zimbra patch immediately and hunt for signs of persistence using the provided IOCs from the multi-agency advisory.
Russian state-sponsored APT (LAUNDRY BEAR) exploiting a view-based zero-day in Zimbra Collaboration Suite. Simply viewing a malicious email exfiltrates 90 days of mail and Global Address List. Patched November 2025 but still actively exploited against US and Ukraine government/defense targets. Multi-agency advisory (CISA, NCSC, etc.) with IOCs. Enterprise SOCs must patch Zimbra urgently and hunt for persistence.