Year-long Russian attacks infect users as soon as they look at an email
ID: 0e27c7eb-f340-509e-8089-0ad2198e24af
STIX ID: report--0e27c7eb-f340-509e-8089-0ad2198e24af
Feed Name: The Register (Security)
A joint alert from 27 international agencies attributes persistent intrusions since July 2025 to the Russian-linked APT 'Laundry Bear' (Void Blizzard), which exploited a Zimbra webmail XSS (CVE-2025-66376) to automatically execute JavaScript when messages were viewed and exfiltrate up to 90 days of email, credentials, directory data, 2FA tokens, and app passcodes; operators used a Python/Docker 'Flowerbed' collection framework hosted on VPS infrastructure and organizations are urged to apply Zimbra patches and review provided IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
