logo

Russian APT 'Laundry Bear' Exploited Zimbra Zero-Day with Half-Click Email Attack

ID: 02a1eb95-1218-5587-b702-74acd81674e7

STIX ID: report--02a1eb95-1218-5587-b702-74acd81674e7

Feed Name: CosmicBytez Labs

Threat Score
92/100

Date Published: 2026-07-26

Date Updated: 2026-07-27

...
...

**Executive Summary:** A Russia-backed APT known as Laundry Bear exploited a stored XSS zero-day (CVE-2025-66376) in Zimbra's Classic UI using a 'half-click' HTML email technique to execute JavaScript (ZimReaper/Ulej), exfiltrate up to 90 days of email, credentials, GAL entries and 2FA/TOTP tokens, mint application-specific 'ZimbraWeb' passwords to bypass MFA and obtain persistent IMAP/SMTP access across government, defense, energy, and NGO targets; organizations must patch to Zimbra 10.1.13 and revoke all application-specific passwords and investigate potential compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.