Back to Feed
Nation-stateJul 23, 2026

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

Russian hackers exploit Zimbra zero-day via phishing emails targeting US and Ukraine.

Vendor Watch

Run Zimbra?

Get an email when a reviewed story names Zimbra, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch worksPrivacy

Summary

A Russian state-sponsored threat group, identified as 'Laundry Bear,' is actively exploiting a zero-day vulnerability in Zimbra collaboration software. The attackers are using a sophisticated 'half-click' phishing technique, where simply opening or previewing a specially crafted email can trigger the exploit. This campaign primarily targets organizations in the United States and Ukraine.

Indicators of Compromise

  • malware — half-click

Entities

Laundry Bear (threat_actor)Zimbra (product)