Nation-stateJul 23, 2026
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
Russian hackers exploit Zimbra zero-day via phishing emails targeting US and Ukraine.
Vendor Watch
Run Zimbra?
Get an email when a reviewed story names Zimbra, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch worksPrivacy
Summary
A Russian state-sponsored threat group, identified as 'Laundry Bear,' is actively exploiting a zero-day vulnerability in Zimbra collaboration software. The attackers are using a sophisticated 'half-click' phishing technique, where simply opening or previewing a specially crafted email can trigger the exploit. This campaign primarily targets organizations in the United States and Ukraine.
Indicators of Compromise
- malware — half-click
Entities
Laundry Bear (threat_actor)Zimbra (product)