CISA Cybersecurity Alert: Russian Spies Turn Zimbra Email Viewing Into an Attack
CISA cybersecurity agencies issued a multinational warning after Russian state-supported actors compromised more than 10 organizations through malicious emails that required no link click.
The July 23 advisory attributes the campaign to LAUNDRY BEAR, an advanced persistent threat group focused on intelligence collection. Since at least July 2025, the group has targeted Western governments, defense organizations, technology companies, schools, media outlets, and other Zimbra users.
The attack changes the familiar bargain behind phishing defense. Employees were taught that avoiding suspicious links and attachments would protect them. Here, opening or previewing an email in a vulnerable Zimbra client was enough to trigger the exploit.
That distinction makes this more than another state-backed phishing report. The campaign shifted a decisive part of email security from user judgment to software patching, browser behavior, monitoring, and incident response.
CISA Cybersecurity Agencies Expose a Yearlong Zimbra Campaign
The central warning is direct: an attacker could compromise an authenticated mailbox when its owner merely viewed a crafted message.
The joint cybersecurity advisory describes operations involving the Zimbra Collaboration Suite, commonly called ZCS. Zimbra combines webmail, calendars, contacts, file tools, and administrative services within an organization-controlled deployment.
The campaign exploited CVE-2025-66376, a stored cross-site scripting vulnerability in Zimbra’s Classic user interface. Stored cross-site scripting lets attacker-controlled code execute when an application displays content that it failed to sanitize safely.
LAUNDRY BEAR embedded its exploit inside an HTML email. The vulnerable interface processed a malicious Cascading Style Sheets @import directive when the message appeared. That process allowed external content to execute JavaScript within the victim’s authenticated Zimbra session.
The user did not need to download a file, enter credentials, or follow an external link. Opening or previewing the message supplied the limited interaction needed to start the compromise.
Government agencies call this a view-based exploit. Some reports describe it as zero-click because no deliberate security decision follows delivery. Proofpoint uses the more precise term “half-click,” since a recipient must still open or preview the email.
The difference matters for technical analysis, but it offers little comfort to defenders. Preview panes and normal inbox use can render a message without any behavior that an employee would recognize as dangerous.
According to CISA, LAUNDRY BEAR successfully targeted more than 10 organizations from July 2025 onward. The affected sectors included the defense industrial base, federal and local government, law enforcement, technology, education, media, and nongovernmental organizations.
The advisory does not provide a complete victim list. That omission protects affected entities, but it also limits external assessments of the campaign’s scale and operational impact.
The group initially used CVE-2025-66376 as a zero-day, meaning defenders lacked an available vendor fix during early exploitation. Zimbra released patched versions in November 2025, but the attackers continued finding vulnerable deployments afterward.
Zimbra’s security advisory identifies versions 10.1.13 and 10.0.18 as containing the relevant correction. The fix addressed abuse of CSS import directives in email HTML within the Classic interface.
This timeline creates the first major tension in the case. The exploit began as an unknown software weakness, but the continuing campaign increasingly depends on organizations leaving a published fix unapplied.
Patch availability therefore divides the incident into two periods. Before November, affected administrators had limited defensive options. After November, delayed upgrades and incomplete remediation became central exposure factors.
The CISA cybersecurity warning arrived eight months after the vendor’s patch. Its timing suggests that exploitation remained important enough to justify coordinated disclosure by numerous security and intelligence agencies.
Those partners included agencies from the United States, Australia, Canada, New Zealand, the United Kingdom, and several European countries. Their participation reflects the campaign’s geographic reach and its focus on Western institutions.
The advisory also connects the operation to a wider pattern of Russian intelligence collection. LAUNDRY BEAR seeks communications, credentials, contacts, and authentication material that can support longer-term access and further targeting.
That objective explains why Zimbra was valuable. A compromised mailbox does not contain only messages. It can reveal organizational relationships, future meetings, internal disputes, operational plans, and trusted contacts for later campaigns.
The Attack Bypassed the Human Firewall
The campaign’s most important reversal is that a cautious employee could follow standard phishing advice and still lose control of a vulnerable mailbox.
Most phishing awareness programs teach users to inspect sender addresses, distrust urgent requests, avoid unknown attachments, and verify links. Those practices remain useful against credential theft and conventional malware delivery.
They do not stop malicious code that executes during email rendering. In this case, the decisive security failure occurred inside the webmail client before the user faced a meaningful choice.
Proofpoint’s technical investigation says the exploit was embedded directly in the message body. It fired when the victim opened or previewed the message in a vulnerable Zimbra client.
The company tracks the observed activity as TA488. It reports circumstantial similarities with Void Blizzard, another industry name associated with LAUNDRY BEAR.
Threat-intelligence labels do not always map perfectly across organizations. Each research team builds clusters from its own telemetry, infrastructure, targeting, malware, and operational behavior.
Proofpoint said it could not independently make a high-confidence attribution from direct telemetry alone. However, its collaboration with U.S. government partners confirmed the association described publicly.
That qualification is important. The multinational advisory makes a strong state-support assessment, while one private company describes limits in what its data alone establishes.
The broader conclusion still rests on more than a single malicious message. Researchers observed consistent targeting, infrastructure patterns, email-collection objectives, and operational links associated with Russian intelligence interests.
The group sent messages from attacker-controlled Proton Mail accounts and previously compromised addresses. A message from a legitimate but stolen account can pass casual sender checks and exploit existing trust.
One documented lure claimed to involve cooperation between European institutions fighting disinformation. It included a legitimate-looking European Union event link, but that link was not the attack’s essential mechanism.
The dangerous code was already inside the email. A recipient could distrust the visible link and avoid it completely, yet trigger the exploit by reading the message.
This design reverses the usual relationship between persuasion and compromise. Traditional phishing succeeds when a lure convinces someone to act. The Zimbra campaign needed the message to render, not the story to persuade.
Security teams often describe employees as a human firewall. That metaphor assigns people a frontline filtering role, especially when technical controls miss a malicious message.
LAUNDRY BEAR’s operation demonstrates the metaphor’s limit. A person cannot make a safe decision when the application executes hostile code before presenting a meaningful choice.
This does not make employee education obsolete. Training still helps users recognize account abuse, unusual prompts, suspicious follow-ups, and conventional phishing attempts.
However, training cannot substitute for secure rendering, rapid patch deployment, server monitoring, and restricted administrative exposure. Treating it as a substitute leaves a predictable gap.
Organizations using self-hosted collaboration software face a particular burden. They gain deployment control, but they also own upgrade planning, compatibility testing, maintenance windows, log retention, and compromise assessment.
That burden grows when a server supports daily communication. Administrators can hesitate to patch because mail downtime disrupts nearly every department.
Attackers benefit from the same hesitation. Once a reliable exploit becomes public, they can scan for exposed systems and target deployments that remain behind the supported release.
The real contest is therefore not attackers against better-informed employees. It is adversary operating speed against an organization’s ability to inventory, patch, detect, and recover.
Ulej Turned One Viewed Message Into Broad Intelligence Access
LAUNDRY BEAR built Ulej to convert an email-rendering flaw into systematic collection, persistence, and controlled exfiltration.
Ulej is the custom capability named in the government advisory. It delivered staged JavaScript through the vulnerable Zimbra interface and operated inside the victim’s authenticated session.
That position gave the code access associated with the mailbox owner. The attacker did not need to recreate every authentication step after the exploit began.
The collection reportedly included as much as 90 days of email. Recent correspondence can expose current projects, active negotiations, travel, personnel matters, investigations, and other time-sensitive intelligence.
Ulej also sought email addresses, passwords, search history, mailbox metadata, and organizational directory information. The Global Address List can reveal employees, roles, teams, and relationships across an institution.
Such directory data has value beyond the first compromise. It can help an operator identify senior officials, technical administrators, project leaders, outside partners, and more promising phishing targets.
The tool also targeted two-factor authentication material and recovery information. Two-factor authentication adds a second verification step, but stolen session data or recovery mechanisms can weaken its protection.
Application passcodes created another persistence route. These passwords let older or specialized applications access an account without repeating the normal interactive authentication flow.
The agencies identified unauthorized passcodes named “ZimbraWeb” as a particularly strong sign of malicious activity in this campaign. Legitimate application passcodes can exist, so defenders must evaluate names alongside creation times and account behavior.
Installing the patch prevents continued exploitation of the specific vulnerability. It does not automatically remove stolen credentials, malicious passcodes, active sessions, or previously collected data.
That point separates patching from remediation. A server can be fully updated today and still contain accounts compromised before the maintenance window.
Affected organizations must therefore investigate mailbox access, authentication activity, application passcodes, suspicious forwarding behavior, and connections to published infrastructure indicators.
CISA says the stolen information was almost certainly transferred for review and long-term retention. Once correspondence reaches adversary-controlled infrastructure, local cleanup cannot retrieve it.
The campaign used a backend environment called Flowerbed, according to the joint analysis. Its Docker-based services received, processed, and stored data collected by Ulej.
One component, called Catcher, acted as a DNS and HTTP server. DNS and web traffic can provide flexible paths for staging or transferring information from targeted environments.
The operators also used automated certificate services. Encrypted connections backed by ordinary certificates can resemble routine web traffic during a superficial review.
Investigators observed rented cloud infrastructure and commercial virtual private network services. These resources help operators separate their personal locations from campaign activity.
The group reportedly replaced parts of its infrastructure every seven to 60 days. Rotation reduces the useful life of simple blocklists and complicates long-term correlation.
Government analysts also found signs that artificial intelligence assisted development of the relatively simple Flowerbed codebase. That observation does not mean AI designed the campaign or discovered the vulnerability.
It points instead to a practical use of coding assistance. Operators can generate utility code, adapt infrastructure, and reduce development time without creating unusually advanced software.
The campaign’s effectiveness came from integration, not one spectacular component. The actors combined a rendering flaw, mailbox privileges, targeted data collection, cloud hosting, encryption, and infrastructure rotation.
That combination also explains why vulnerability severity scores can mislead. A flaw’s operational impact depends on where it sits, what privileges it reaches, and how an adversary weaponizes it.
Email represents an unusually rich target. A single mailbox can provide credentials, sensitive content, future lures, organizational maps, and access to password-reset workflows.
A stored cross-site scripting bug may sound narrower than remote server takeover. Inside authenticated webmail, however, it can expose exactly the information an espionage group wants.
A Patch Ends the Exploit, Not the Incident
Organizations that only install the update risk closing the original doorway while leaving the attacker’s copied keys and stolen intelligence unaddressed.
Zimbra published the relevant fixes in versions 10.1.13 and 10.0.18 on November 6, 2025. Its patch announcement classified the security severity as high.
Administrators should move to the latest supported release rather than treating those historical versions as permanent destinations. Later releases can include additional security and maintenance corrections.
Where immediate patching is impossible, agencies recommend moving users away from the vulnerable web interface. That measure reduces exposure, but it should remain temporary.
Any internet-facing Zimbra deployment that stayed vulnerable after July 2025 deserves investigation. Absence of an obvious alert does not establish absence of compromise.
The exploit did not require malware installation on a workstation. Its activity could appear through web requests, account operations, application passcode creation, or connections to rotating external infrastructure.
Organizations should compare available logs with the advisory’s indicators of compromise. They should also search for suspicious external requests associated with messages viewed in the Classic interface.
Authentication reviews should identify unusual locations, new devices, abnormal session timing, and access that continues after password changes. Administrators should revoke sessions and reset affected credentials where evidence supports compromise.
Teams should inspect application passcodes, especially those named “ZimbraWeb.” They should validate each passcode with the account owner and remove entries lacking a legitimate operational purpose.
Password resets alone may be insufficient. An attacker holding a valid application passcode, session artifact, or recovery mechanism can retain access through a route defenders overlook.
Mailbox rules and forwarding settings also deserve inspection. An intruder can use them to copy future messages or hide selected correspondence without repeatedly exploiting the original flaw.
Responders must consider downstream identity systems. Email often supports password resets and account recovery for unrelated services, creating opportunities for lateral compromise.
The campaign also raises a difficult evidence problem. Some organizations may lack the historical logs needed to reconstruct activity that began a year earlier.
Short retention periods reduce storage costs, but they can erase the record needed to investigate quiet espionage. The tradeoff becomes visible only after a delayed public disclosure.
Even strong logs may not answer whether every message was read by a human analyst after exfiltration. Incident reports should distinguish verified collection from assumptions about later intelligence use.
Attribution requires similar discipline. CISA, the NSA, the FBI, and allied agencies assess LAUNDRY BEAR as Russian state-supported. Dutch intelligence originally named the group after investigating earlier operations.
The Netherlands’ AIVD and MIVD linked LAUNDRY BEAR to compromises beginning in at least 2024. A 2024 breach affecting Dutch police exposed work-related contact information.
The new Zimbra advisory extends public understanding of the group’s methods. It does not disclose every source behind the governments’ attribution judgment.
Russian officials generally reject Western accusations concerning state-directed cyber operations. The absence of a public Russian response to each technical claim does not independently validate or disprove the advisory.
Defenders do not need to resolve the geopolitical dispute before acting. The vulnerability exists, the vendor patched it, and multiple investigators observed exploitation consistent with the disclosed technique.
The practical response should therefore separate two questions. Attribution guides strategic understanding, while observable artifacts guide local detection and remediation.
Organizations should also avoid overgeneralizing the victim count. “More than 10” describes confirmed successful targets known to the agencies, not a reliable ceiling for global exposure.
Some compromises remain undiscovered. Others may be known privately but excluded from public reporting. Conversely, an unpatched server should not automatically be counted as compromised without supporting evidence.
The best defensible conclusion is narrower. Vulnerable Zimbra installations faced a demonstrated attack path, and the responsible operation actively pursued sensitive Western communications.
What Defenders Should Watch After the CISA Cybersecurity Warning
The next phase depends on patch adoption, evidence of migration to other mail platforms, and disclosures that clarify the campaign’s true reach.
The first signal is the rate at which exposed Zimbra systems disappear or move onto supported versions. Rapid patch adoption would shrink the group’s easiest remaining target pool.
That outcome would strengthen the view that coordinated disclosure can contain the current exploit. Continued exposure months later would show that operational patch barriers remain the attacker’s durable advantage.
Administrators should verify version status through asset inventories, not employee surveys or procurement records. A purchased support contract does not prove that every production node received the update.
The second signal is whether LAUNDRY BEAR adapts Ulej’s view-based technique to another vulnerability or email platform. The advisory explicitly warns that the capability has adaptation potential.
The Zimbra flaw is product-specific, but the strategy is broader. Any webmail renderer that processes attacker-controlled content inside an authenticated session can present valuable risk.
Proofpoint has separately documented other Russian groups using half-click exploits against webmail servers. That history suggests email rendering will remain an attractive espionage surface after CVE-2025-66376 loses value.
A new campaign against another platform would strengthen the article’s central judgment. It would show that view-based compromise is an operational method, not a one-product anomaly.
Failure to observe adaptation would weaken the broader forecast, although intelligence operations often remain hidden for long periods. Public silence cannot prove the technique was abandoned.
The third signal is whether agencies or incident responders identify additional victims, stolen-data effects, or persistence after patching. Those disclosures would clarify the cost of delayed remediation.
More confirmed victims would show that the published figure represented only an early floor. Evidence of continued access through passcodes or sessions would reinforce the distinction between updating and recovering.
By contrast, limited additional findings could indicate that the campaign remained selective. LAUNDRY BEAR appears focused on intelligence value rather than indiscriminate criminal monetization.
Organizations should not wait for those public signals before reviewing their environments. They can take several concrete actions now.
First, inventory every Zimbra server, interface, and exposed service. Confirm that each deployment runs a current supported version and that no forgotten test instance remains reachable.
Second, preserve relevant logs before routine retention policies remove them. Investigators need web, authentication, mailbox, proxy, DNS, and endpoint records to reconstruct activity.
Third, hunt for the published domains, addresses, certificate patterns, and passcode names. Indicators expire, so combine them with behavioral searches rather than using blocklists alone.
Fourth, revoke suspicious sessions and credentials after collecting evidence. Coordinate these steps carefully because premature resets can alert an operator or destroy useful investigative context.
Fifth, review outbound traffic from webmail users and servers. Unexpected DNS or HTTP activity near message-view events can help identify rendering-based exploitation.
Sixth, prepare a response path for sensitive email exposure. Legal, executive, security, communications, and affected business teams should agree on escalation before investigators confirm theft.
The NSA warning emphasizes updating software, monitoring mail services, and applying the advisory’s mitigations. Those steps form a baseline, not a complete security strategy.
Longer-term defenses should reduce the trust granted to rendered email content. They should also isolate collaboration services, restrict outbound communications, and monitor sensitive account actions.
Organizations need patch processes that reflect exploitation evidence, not only a vulnerability’s headline score. A medium-looking bug in an intelligence-rich system can demand emergency treatment.
Security leaders should also revise training messages carefully. Employees should still avoid suspicious links and attachments, but leaders must stop implying that user caution can prevent every email compromise.
The more accurate message assigns responsibility across layers. Users report anomalies, administrators patch systems, engineers limit dangerous rendering, and responders investigate identity persistence.
That shared model matters because LAUNDRY BEAR did not defeat an employee in a contest of judgment. It exploited software during an ordinary action that organizations require employees to perform.
The CISA cybersecurity advisory therefore leaves one urgent question for every Zimbra operator: can your team prove the server was patched, and can it prove attackers did not arrive first?



