US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
ID: f2aa41b4-ae03-56f6-8d22-939f973758f5
STIX ID: report--f2aa41b4-ae03-56f6-8d22-939f973758f5
Feed Name: Security Affairs
US and international security agencies warn that the Russia-linked APT 'Laundry Bear' exploited a Zimbra Collaboration zero-day (CVE-2025-66376) to execute JavaScript in viewed emails (zero-click), enabling credential theft, mailbox access persistence (IMAP enablement, application passwords), and exfiltration via attacker infrastructure (Flowerbed/Catcher). The advisory includes IOCs (malicious domains), technical details of the multi-stage payload and obfuscation, and remediation guidance including patching Zimbra, reviewing IOCs and authentication anomalies, and enforcing phishing-resistant MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
