logo

US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers

ID: f2aa41b4-ae03-56f6-8d22-939f973758f5

STIX ID: report--f2aa41b4-ae03-56f6-8d22-939f973758f5

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Pierluigi Paganini

...
...

US and international security agencies warn that the Russia-linked APT 'Laundry Bear' exploited a Zimbra Collaboration zero-day (CVE-2025-66376) to execute JavaScript in viewed emails (zero-click), enabling credential theft, mailbox access persistence (IMAP enablement, application passwords), and exfiltration via attacker infrastructure (Flowerbed/Catcher). The advisory includes IOCs (malicious domains), technical details of the multi-stage payload and obfuscation, and remediation guidance including patching Zimbra, reviewing IOCs and authentication anomalies, and enforcing phishing-resistant MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.