logo

Year-long Russian attacks infect users as soon as they look at an email

ID: 0e27c7eb-f340-509e-8089-0ad2198e24af

STIX ID: report--0e27c7eb-f340-509e-8089-0ad2198e24af

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

...
...

A joint alert from 27 international agencies attributes persistent intrusions since July 2025 to the Russian-linked APT 'Laundry Bear' (Void Blizzard), which exploited a Zimbra webmail XSS (CVE-2025-66376) to automatically execute JavaScript when messages were viewed and exfiltrate up to 90 days of email, credentials, directory data, 2FA tokens, and app passcodes; operators used a Python/Docker 'Flowerbed' collection framework hosted on VPS infrastructure and organizations are urged to apply Zimbra patches and review provided IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.