Jul 23, 2026
Policy

Zimbra Russian attack steals email when messages are viewed

A 27-agency alert says Russia-linked Laundry Bear exploited a Zimbra flaw to access email systems across government and industry.

Renata Fuchs

By Renata Fuchs · Policy Reporter

· 3 min read

Zimbra Russian attack steals email when messages are viewed
Photo: The Register

A Zimbra Russian attack attributed to a Kremlin-linked hacking group has been used for at least a year to break into government and commercial email systems, according to a joint alert from 27 US, UK and other international agencies. The campaign matters to security teams because the exploit can run when a target views a malicious email, without requiring a link click or attachment open.

The agencies attribute the intrusions to Laundry Bear, also known as Void Blizzard, and said the group is “almost certainly” collecting sensitive information for the Russian Federation. The alert says the campaign has focused on covert access to email data across Western organizations.

The operation targets CVE-2025-66376, a cross-site scripting vulnerability in the Zimbra Collaboration Suite, the web-based email and collaboration platform. Zimbra patched the flaw in November 2025, but the agencies said the Russian actors had been exploiting it before then, with activity ongoing since July 2025.

How does the Zimbra Russian attack work?

The agencies said attackers send HTML emails containing malicious JavaScript to organizations using vulnerable Zimbra webmail. When a victim views the email in the web client, the script can execute through the cross-site scripting flaw, giving the attackers a path to collect data from the account.

The alert says no further user action is needed beyond viewing the message. That removes one of the common failure points in phishing campaigns, where defenders train users not to click links or open files, and shifts the burden toward patching, client exposure reduction and detection.

According to the agencies, targeted organizations include the defense industrial base, federal and local government, education, energy, law enforcement, media, non-governmental organizations and technology. The alert listed several email addresses used in the campaign, including ivanka.zurabishvili@proton[.]me, zmul1@buildandconsulting[.]com, garrysmithme@pinmx[.]net and hostingclient@pinmx[.]net.

Once inside an account, Laundry Bear has exfiltrated large amounts of email-related data, the agencies said. That includes the prior 90 days of victims’ email communications, email addresses and passwords, organizational email directories such as global address lists, two-factor authentication tokens and newly created application passcodes.

The agencies said the group then uses stolen credentials to preserve access to victims’ mailboxes. Its activity includes changing account preferences and collecting authentication information, which can give attackers a way back into accounts even after the initial message is found.

What did agencies say about Flowerbed?

The stolen data is stored on an unattributable virtual private server running a custom collection framework called Flowerbed, according to the alert. The agencies described Flowerbed as a Python project that uses Docker for containerization.

The alert also said the “simplistic” Flowerbed codebase shows indications that artificial intelligence played a role in its development. The agencies did not identify a specific AI tool or provide a baseline for how much of the framework may have been generated that way.

The 31-page alert includes indicators of compromise intended to help organizations identify affected users. The agencies recommend that organizations reduce employees’ use of the Zimbra Collaboration Suite webmail client until they have updated to a version patched against CVE-2025-66376.

This story draws on original reporting from The Register.

More from Policy

All Policy →