< Back to all clusters
[CRIME] · Germany, United States, Ukraine, Russia · 8 sources

Laundry Bear exploits Zimbra email suite with zero‑click attack

The Russian‑state‑backed hacking group known as Laundry Bear is running a campaign that exploits a critical zero‑click vulnerability (CVE‑2025‑66376) in the Zimbra Collaboration Suite. The flaw—present in Zimbra versions prior to 10.0.18 and 10.1.13—allows malicious JavaScript code to execute automatically when a user merely opens a crafted email, without clicking links or downloading attachments.

The attackers have used the exploit to steal large volumes of data from targeted organisations, including emails, global address lists, passwords and two‑factor‑authentication tokens. Their focus has been on NATO member states, Ukraine, the United States and various entities in Africa. Evidence shows the group operates its infrastructure on Docker containers hosted on rented cloud servers and routes traffic through the Mullvad VPN service. The campaign has been active since at least July 2025 and is tracked by security firms such as Proofpoint, which refers to the technique as a “Half‑Click Exploit” and labels the actors as TA488.

Entities: CVE‑2025‑66376 · Docker · Laundry Bear · Mullvad · Zimbra Collaboration Suite

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

  • [○ 1 SOURCE] The campaign targeted NATO member states, Ukraine, the United States and regions in Africa. (First article (id 844f4e6f...).)
  • [● 2 SOURCES] The exploit allows infection by merely opening an email, without clicking links or downloading attachments. (Both articles.)
  • [○ 1 SOURCE] Proofpoint identifies the actors as TA488 and refers to the technique as a “Half‑Click Exploit”. (Second article.)
  • [○ 1 SOURCE] The group uses Docker containers on rented cloud servers and routes traffic through Mullvad VPN. (First article.)
  • [○ 1 SOURCE] Vulnerable Zimbra versions are before 10.0.18 and before 10.1.13. (Second article (id 70b73005...).)
  • [○ 1 SOURCE] The campaign has been active since at least July 2025. (Second article.)
  • [○ 1 SOURCE] Attackers stole emails, global address lists, passwords and two‑factor authentication tokens. (First article.)
  • [● 2 SOURCES] Laundry Bear exploited a zero‑click vulnerability in Zimbra Collaboration Suite identified as CVE‑2025‑66376. (Both articles (ids 844f4e6f... and 70b73005...).)