Back to Feed
Nation-stateJul 23, 2026

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

Russian hackers exploit Zimbra zero-day via phishing emails targeting US and Ukraine.

Summary

A Russian state-sponsored threat group, identified as 'Laundry Bear,' is actively exploiting a zero-day vulnerability in Zimbra collaboration software. The attackers are using a sophisticated 'half-click' phishing technique, where simply opening or previewing a specially crafted email can trigger the exploit. This campaign primarily targets organizations in the United States and Ukraine.

Indicators of Compromise

  • malware — half-click

Entities

Laundry Bear (threat_actor)Zimbra (product)