INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Russian Hackers Exploit Zimbra Zero-Day Against US Ukraine Targets

| 2026-07-23 16:49 CRITICAL HIGH
Executive Summary AI-generated
Russian hackers have been exploiting a recently discovered zero-day vulnerability in the Zimbra Collaboration Suite (ZCS) to compromise networks of Western governments and enterprises, according to intelligence and cybersecurity agencies worldwide. The threat actors behind this campaign are state-backed and have been linked to other advanced persistent threats (APTs), including "Laundry Bear," which has targeted Ukrainian government entities but also US government agencies, defense companies, and scientific organizations. This latest attack marks another example of Russian APTs seeking sensitive information for the Russian Federation. The Laundry Bear attacks demonstrate a growing threat from these actors against US organizations, underscoring the need for increased vigilance and cooperation among nations to counter this emerging cyber threat.
Technical Mitigations AI-generated
* Implement a robust email security solution that includes: + Thoroughly scanning and filtering emails for suspicious content + Using multi-factor authentication (MFA) to prevent unauthorized access + Regularly updating software, plugins, and operating systems to patch known vulnerabilities + Employing advanced threat detection and response tools * Conduct regular email security awareness training for employees to educate them on: + How to identify phishing emails and report suspicious activity + The importance of using strong passwords and keeping personal devices secure + Best practices for avoiding click-through traps, attachments, and links * Use a web application firewall (WAF) that includes: + Intrusion detection and prevention capabilities + Advanced threat protection features to detect and block known and unknown threats + Support for sandboxing and reverse proxy technologies to isolate sensitive data * Regularly review and update email security configurations, including: + Setting up secure protocols such as TLS 1.2 or higher + Configuring IP blocking and rate limiting to prevent abuse + Implementing a content filtering system that blocks known phishing sites and malware These technical mitigations can help protect organizations from the Laundry Bear threat by reducing the attack surface, improving email security awareness, and enhancing overall web application security.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation GhostMailOperation GhostMail APT29APT29APT28APT28Winter VivernWinter Vivern SofacySofacySednitSednit CVE-2025-66376CVE-2025-66376 CVE-2020-7796CVE-2020-7796 CVE-2025-68645CVE-2025-68645 CVE-2025-48700CVE-2025-48700
Target & Sectors
BENELUX BENELUX NORTH_AMERICA NORTH_AMERICA defensedefense transportationtransportation energyenergy aviationaviation educationeducation mediamedia technologytechnology maritimemaritime governmentgovernment
Incident Timeline
‎February 2023
The Russian-sponsored Winter Vivern hacking group used a reflected XSS exploit to breach Zimbra webmail portals.
target_region Russian Federation
attribution NATO
industry Government
threat_actor Winter Vivern
‎at least 2024
Threat actors exploited a critical Zero-Trust Zimbra XSS flaw in the affected organization's email system to gain unauthorized access and compromise user mailboxes.
target_region Russian Federation
target_region Ukraine
attribution NATO
‎October 2024
Threat actors used a previously abused Zimbra XSS flaw to target and compromise vulnerable mailboxes.
target_region Russian Federation
threat_actor APT29
attribution Foreign Intelligence Service
‎May 2025
The Laundry Bear hacking group exploited a critical Zero-Trust Access Vulnerability in Zimbra email servers to target governments and police agencies.
source_region Ukraine
source_region Netherlands
‎2025/07/23
Threat actors used a "novel exploit" for CVE-2025-66376 to target mailboxes.
tactic Phishing
vulnerability CVE-2025-66376
‎July 2025
Threat actors used a Zero-Trust Security Control in Zimbra to target mailboxes.
industry Government
target_region United States
attribution ZCS
attribution APT
‎November 2025
Laundry Bear exploited a zero-day XSS flaw in Zimbra's version 10.1.13 to target organizations running unpatched servers until November 2025.
attribution Laundry Bear
attribution CISA
vulnerability CVE-2025-66376
infrastructure 10.1.13
organisation CVE-2025
‎January 22
Threat actors exploited a critical Zero-Trust Access Insecurity Boosting (Zimbra XSS Flaw) in the compromised student email to gain unauthorized access.
industry Maritime
‎March 17
Russian threat actors exploited CVE-2025-66376 in the compromise of a Ukrainian government agency on March 17.
source_region Russian Federation
target_region Ukraine
industry Government
vulnerability CVE-2025-66376
attribution Seqrite
‎March 18
Threat actors exploited a Critical Zimbra XSS Flaw to target mailboxes in the United States.
source_region United States
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
‎2026/07/23
Russian hackers exploited a previously unknown Zimbra XSS vulnerability (CVE-2025-66376) to target Ukrainian government entities.
organisation CVE-2025-66376
threat_actor APT28
organisation APT
organisation BlueDelta
organisation BleepingComputer
organisation HTML
organisation Laundry Bear
organisation AiTM
organisation ZCS
organisation State Hydrology Agency
organisation a Zimbra XSS
infrastructure 1.13
organisation CSS
organisation Zimbra Collaboration Suite's
organisation Synacor
organisation IMAP
organisation ActiveSync
organisation MFA
organisation DNS
organisation HTTPS
organisation IP
organisation ZimbraWeb
organisation Microsoft
organisation EDR
organisation Frozen-Food Chain Laundry Bear's 'Half-Click'
organisation CVE-2025-48700
organisation Shadowserver
organisation Operation GhostMail
organisation Seqrite
infrastructure 10.1.19
organisation the Classic Web Client
organisation ZCS v10.1.19
organisation Google’s Threat Analysis Group
organisation SecurityAffairs
organisation the Classic UI
organisation Ajax
organisation Google
organisation Threat Analysis Group
‎the beginning of 2026
Threat actors exploited a Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability to target mailboxes.
vulnerability CVE-2025-66376
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
vulnerability CVE-2025-68645
vulnerability CVE-2020-7796
vulnerability CVSS score of 8.8
vulnerability CVSS score of 9.8
vulnerability CVSS score of 7.2
attribution CVSS
attribution PHP Remote File Inclusion Vulnerability
tactic T1584.004 - Server
general_metric 1 CISA
general_metric 2 CISA
Tactical Metrics
Metrics
infrastructure
‎10.1.13
Software Version
Metrics
infrastructure
‎1.13
Software Version
Metrics
infrastructure
‎10.1.19
Software Version
Intelligence Sources