On July 23, 2026, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with several national and international agencies, released a joint Cybersecurity Advisory (CSA) detailing how a Russian state-supported adversary has targeted and compromised government and commercial organizations across Western countries through the exploitation of the Zimbra Collaboration Suite (ZCS) since at least July 2025. The activity is tracked by the cybersecurity community under several names, primarily as Laundry Bear, a designation initially introduced by the Netherlands’ General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD).
Laundry Bear’s activities are almost certainly intended to collect sensitive information on behalf of the Russian Federation, with a primary focus on the covert acquisition of email data. Previous campaigns relied on unsophisticated initial access techniques, including phishing, password spraying, and pass-the-cookie attacks, allowing the group to successfully conduct high-volume operations. In contrast, the latest campaign targeting the ZCS employed a previously unknown zero-day vulnerability, CVE-2025-66376, which was patched in November 2025 yet continues to be successfully exploited. This evolution demonstrates Laundry Bear’s intent and capability to employ increasingly sophisticated exploitation techniques in support of its intelligence collection objectives.
Unlike traditional phishing campaigns, which rely on persuading users to perform an action, such as clicking a link or opening a malicious attachment, Laundry Bear’s latest campaign leverages a view-based exploit that requires only that a user open a malicious email in a vulnerable version of the Zimbra webmail interface. Once rendered, the exploit attempts to exfiltrate the victim’s previous 90 days of email communications, the organization’s Global Address List (GAL), and other sensitive information to infrastructure controlled by the adversary.
Given the urgency and sophistication of this threat, AttackIQ has introduced the following scenarios to help organizations validate their defenses against the techniques employed by Laundry Bear. These include an email-based scenario that replicates the adversary’s Initial Access and Exploitation technique, along with nine network-based scenarios that emulate the associated Command and Control (C2) and Exfiltration communications:
- Send Laundry Bear’s Ukrainian Internship Phishing Lure (AA24-204A)
- Laundry Bear’s Session Initiation Beacon via HTTPS POST Request
- Laundry Bear’s Plaintext Password Exfiltration via HTTPS POST Request
- Laundry Bear’s Session Completion Beacon via HTTPS POST Request
- Laundry Bear’s SOAP Response Exfiltration via HTTPS POST Request
- Laundry Bear’s Email Archive Exfiltration to HTTPS POST Request
- Laundry Bear’s Zimbra Account Reconnaissance via SOAP GetInfoRequest
- Laundry Bear’s 2FA Scratch Code Harvesting via SOAP GetScratchCodesRequest
- Laundry Bear’s Mobile Device Enumeration via SOAP GetDeviceStatusRequest
- Laundry Bear’s OAuth Token Harvesting via SOAP GetOAuthConsumersRequest
Detection and Mitigation Opportunities
AttackIQ strongly recommends reviewing and following CISA’s recommendations, provided in the advisory, to aid in detecting and mitigating this malicious activity. These steps can help organizations identify and mitigate the risks associated with fast flux networks and improve overall cybersecurity posture:
In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.
All organizations that use the ZCS webmail service should immediately prioritize ensuring that their ZCS is not running a vulnerable version. A patch for CVE-2025-66376 was released for both 10.1.13 and 10.0.18 versions of ZCS. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version.
System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates. Administrators can maintain awareness of active vulnerability exploitation by referencing open-source resources, including CISA’s Known Exploited Vulnerabilities Catalog and NCSC-UK’s Responding to active exploitation of vulnerabilities guidance.
Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse. However, Application Passcodes may still be necessary and should be monitored closely.
Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage. This will allow organizations to monitor for and identify suspicious network activity, such as:
- Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization;
- Frequent DNS queries for a suspicious domain with seemingly random subdomains;
- A sudden spike of connections to a server associated with a recently established domain; and
- Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN.
Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the Exfiltration section of the advisory.
Wrap-up
In summary, these scenarios will evaluate security and incident response processes and support the improvement of your security control posture against the behaviors exhibited by Laundry Bear. With data generated from continuous testing and use of these scenarios, you can focus your teams on achieving key security outcomes, adjust your security controls, and work to elevate your total security program effectiveness against a known and dangerous threat.
AttackIQ is the industry’s leading Continuous Threat Exposure Management (CTEM) platform, enabling organizations to measure true exposure, prioritize risk, and disrupt real-world attack paths. By moving beyond static vulnerability data, AttackIQ operationalizes CTEM by continuously validating exposures against real adversary behavior and defensive controls. The platform connects vulnerabilities, configurations, identities, and detections into adversary-validated attack paths—quantifying the likelihood of attacker movement and impact. This evidence-based approach empowers security leaders to focus on what matters most, optimize defensive investments, and strengthen resilience through threat-informed, AI-driven security operations.
