Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
ID: 23552b9c-411f-5bf7-8c44-4e1c426a541b
STIX ID: report--23552b9c-411f-5bf7-8c44-4e1c426a541b
Feed Name: Proofpoint Blog
Russian state-aligned APT 'Laundry Bear' conducted a widespread zero-click phishing campaign exploiting a Zimbra webmail vulnerability (CVE-2025-66376) patched in November 2025; attackers used malicious JavaScript in emails to immediately execute on open and attempted to exfiltrate recent emails, credentials, contact lists, and 2FA tokens from compromised accounts. Multiple government agencies and security vendors linked the activity to espionage against Ukrainian, NATO, and other international targets and urged immediate patching or use of alternate mail clients.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
