Back to Feed
Zero-daySep 4, 2026

Protecting Against Zero-Click Attacks

Laundry Bear exploits Zimbra zero-day for espionage against Western organizations.

Summary

Russian state-sponsored threat actor Laundry Bear exploited a zero-day XSS vulnerability in Zimbra Collaboration Suite to conduct espionage against critical industries in the West. The attack, which required no user interaction beyond opening an email, allowed attackers to gain persistence, access emails, and steal sensitive data. Zimbra has released patches, and advisories were issued by the UK's NCSC and 15 other countries.

Full text

By Aimee Steele, threat intelligence analyst at Talion Cyber Security Last month, the UK’s National Cyber Security Centre (NCSC) issued an advisory around a new phishing campaign targeting organisations in the West that was being carried out by the Russian state-sponsored threat actor known as Laundry Bear. The campaign, saw the threat actors exploiting a zero-day vulnerability in Zimbra Collaboration Suite in order to compromise networks, before gaining persistence, accessing emails, stealing sensitive data and conducting espionage against organisations using vulnerable Zimbra Mailservers. The advisory from the NCSC was issued in conjunction with advisories from 15 other countries, including the US, Finland, Australia, Denmark and France, and it advised that the threat actors were targeting critical industries in order to steal sensitive information with Russian government backing. Phishing is nothing new and is regularly cited as the most prevalent method used within cyberattacks. However, what made this attack stand out and warrant such a coordinated international response, was its deviation from conventional phishing techniques, amounting to a markedly sophisticated zero-click campaign. Successful exploitation did not rely on users clicking a link or opening an attachment; victims simply needed to open an email. Typical phishing attacks rely on user interaction. The victim might click on a malicious link or open an attachment. The threat actor might leverage phishing techniques to deploy malware, infiltrate systems or networks and establish backdoors for persistent access. Even at the most basic level, attackers might simply use stolen credentials to access private user accounts, such as a bank account, to commit financial fraud. In this instance, successful exploitation did not depend on outright deception; there were no features that might typically raise a user’s suspicion. The victim didn’t need to do anything at all. So, how did the attackers get in? The campaign The threat group was able to exploit a zero-day XSS vulnerability in the Zimbra Collaboration Suite (CVE-2025-66376), the exploit having been embedded in the HTML body of the message and triggered upon opening or previewing. Emails were issued from either Proton Mail accounts or previously compromised email addresses. Successful exploitation gave attackers access to the webmail server, allowing them to establish persistence, access users’ mailboxes and steal sensitive emails and authentication data. From there, the stolen information could be used to conduct cyber espionage, gather intelligence on government and critical infrastructure organisations, and potentially facilitate further compromise of connected systems. Attackers were also able to leverage their access to target specific victims in spearphishing attempts. In instances such as this, having access to contextual information can add an additional layer of legitimacy to communications. Protecting against Zero-Click attacks Following the discovery of the vulnerability, Zimbra released security updates to address the flaw, and any organisation using affected versions of Zimbra Collaboration Suite should ensure these patches have been applied as a priority. If this is not immediately actionable, it is advisable for organisations to implement another suitable mail client in the meantime. However, patching alone should not be considered sufficient. Organisations should also review logs, monitor for indicators of compromise, investigate unusual authentication activity and assess whether attackers may have gained access before the vulnerability was remediated. Multi-factor authentication, network segmentation and continuous monitoring can also help limit the impact if a compromise does occur. Attacks like these also reinforce the importance of detection and response, which can help spot malicious access quickly, before attackers have an opportunity to compromise networks and access data. Zero-click exploits present a greater challenge to the individual user than typical phishing attempts. However, they can still play an important role in limiting the impact of such attacks by remaining vigilant for unusual login alerts, unexpected password reset notifications or signs that an account has been accessed without permission. Users should also ensure multi-factor authentication is enabled wherever possible, use strong and unique passwords, and be alert for any follow-on phishing attempts, as attackers will often use information stolen during an initial compromise to target victims further. Lessons for organisations Zero-click attacks are particularly deceptive because they present without the typical warning signs users are trained to look out for in social engineering and phishing scams. This recent zero-click campaign by Laundry Bear begs the question as to whether current user awareness training is particularly affective in the prevention of successful phishing attacks, which are becoming increasingly sophisticated. In general, rapid patching supports robust remediation strategy and is fundamental if organisations wish to prevent exploitation, rather than react to it. In addition, continuous monitoring and effective detection and response capabilities are fundamental when reacting efficiently to zero-clicks. Considering the severity of the attack, any organisation using Zimbra Collaboration Suite should ensure they have applied the latest security updates as a priority. Organisations should also assume patching alone is insufficient, and review logs, authentication activity and other indicators of compromise to determine whether they were breached before the vulnerability was remediated. Overall, attacks like these require a layered approach to security, helping identify attackers and potential threats before organisations are compromised further.

Indicators of Compromise

  • cve — CVE-2025-66376

Entities

Laundry Bear (threat_actor)Zimbra Collaboration Suite (product)Zimbra Mailservers (product)Zimbra (vendor)