Nation-stateJul 23, 2026
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
Russian hackers exploit Zimbra zero-day via phishing emails targeting US and Ukraine.
Summary
A Russian state-sponsored threat group, identified as 'Laundry Bear,' is actively exploiting a zero-day vulnerability in Zimbra collaboration software. The attackers are using a sophisticated 'half-click' phishing technique, where simply opening or previewing a specially crafted email can trigger the exploit. This campaign primarily targets organizations in the United States and Ukraine.
Indicators of Compromise
- malware — half-click
Entities
Laundry Bear (threat_actor)Zimbra (product)