Laundry Bear Zero-Click Zimbra Phishing Campaign Warned by CISA

Article Content
On July 23, 2026, an international coalition of cybersecurity agencies—led by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI), alongside the United Kingdom’s National Cyber Security Centre (UK NCSC) and the Netherlands’ AIVD and MIVD—issued a joint cybersecurity advisory (AA26-204A) detailing a cyberespionage campaign targeting enterprise email infrastructure. Spearheaded by the Russian state-supported threat actor known as Laundry Bear (also tracked across the security industry as Void Blizzard, TA488, and CL-STA-1114), this operational effort zeroes in on organizations running on-premises Zimbra Collaboration Suite (ZCS) installations. By moving away from conventional social engineering tactics that require explicit victim interaction, the campaign highlights an operational shift toward silent, view-based zero-click exploitation designed to compromise government and commercial communications.
The campaign’s impact spans a broad cross-section of critical infrastructure and public sectors, including defense industrial base (DIB) contractors, federal and municipal government bodies, energy providers, higher education institutions, technology firms, and diplomatic entities across NATO member states, Ukraine, and allied nations. By exploiting legacy webmail architectures, Laundry Bear has successfully breached mailboxes, harvested strategic intelligence, and established persistent background access without triggering standard user security awareness or session alerts. This editorial examines the technical mechanics behind the attack, the custom surveillance tools deployed, and the essential steps security teams must take to purge these threat actors from compromised networks.
The Evolution of Laundry Bear and the Zero-Click Threat Landscape
Historically, sophisticated threat groups targeting email platforms built their operational cadences around high-volume social engineering. Operations conducted by Russian state-sponsored actors frequently leveraged spear-phishing messages with deceptive web links, credential harvesting landing pages, or malicious file attachments. However, as enterprise defenses evolved—incorporating robust endpoint detection and response (EDR) solutions, advanced email filtering, and widespread security awareness training—the success rate of traditional phishing dropped significantly. In response, advanced persistent threat (APT) groups shifted toward exploiting application-level vulnerabilities within webmail applications themselves.
Known in threat intelligence circles for its historical reliance on credential spraying, pass-the-cookie attacks, and session hijacking, Laundry Bear has elevated its technical capabilities. The transition to “half-click” or “zero-click” view-based exploitation allows the group to bypass traditional user security training entirely. In a zero-click webmail attack, the victim does not need to click a suspicious URL, execute a macro, or download an external payload. Merely opening or previewing an incoming email within a vulnerable web browser interface triggers the execution of adversary code. This vector provides Laundry Bear with an unhindered foothold into target networks while leaving virtually no visible footprint on the end-user’s screen.
Technical Breakdown: CVE-2025-66376 and CSS Weaponization
At the heart of Laundry Bear‘s campaign is the weaponization of CVE-2025-66376, a stored cross-site scripting (XSS) vulnerability residing within the Classic User Interface (UI) of the Zimbra Collaboration Suite. Before initial vendor patches were issued, the threat group exploited this security flaw as a zero-day capability for at least five months. Despite subsequent software updates, unpatched ZCS webmail servers across the globe remain prime targets for automated scanning and retroactive exploitation.
The technical mechanics of the attack hinge on improper input sanitization within Zimbra’s email rendering engine—specifically regarding Cascading Style Sheets (CSS). When parsing incoming HTML emails, the Classic UI failed to adequately sanitize CSS @import directives. This sanitization gap allows an attacker to structure an email message containing an embedded @import rule pointing to an external stylesheet under adversary control. The step-by-step execution flow operates as follows:
- Initial Delivery: The threat actors send a specially crafted HTML email to the target address. To evade basic email reputation filters, Laundry Bear frequently routes these emails through previously compromised accounts within victim infrastructure or allied organizations.
- Automatic Rendering: As soon as the victim views or previews the message in the ZCS Classic UI, the mail client interprets the HTML content and processes the embedded CSS
@importdirective. - Payload Injection: The processing of the malicious stylesheet forces the browser to fetch remote resources, triggering the inline execution of an arbitrary JavaScript payload directly within the user’s active, authenticated Zimbra session context.
- Session Context Hijacking: Because the JavaScript code executes natively within the victim’s authenticated browser tab, it inherits all rights, session cookies, and API permissions granted to that user, completely bypassing browser same-origin policies (SOP).
Inside the Ulej Payload and the Flowerbed Framework
Once the zero-click XSS condition triggers execution, Laundry Bear deploys a specialized, custom JavaScript exfiltration framework known internally as Ulej (derived from the Russian word for “beehive”, also tracked in intelligence reports as “Flowerbed”). Rather than relying on generic post-exploitation scripts, Ulej is designed specifically to interact with Zimbra’s internal REST APIs and SOAP services to systematically strip the account of sensitive intelligence.
Upon initial session execution, the Ulej engine immediately initiates a multi-stage data gathering routine. The tool systematically extracts the following high-value assets from the compromised mailbox:
- Historical Email Communications: Automatically archives and extracts up to the last 90 days of incoming, outgoing, and drafted email messages, including all attached files.
- Global Address List (GAL): Downloads the complete organizational directory, providing the threat actors with internal organizational charts, employee email addresses, phone numbers, and structural mapping for lateral spear-phishing.
- Credential and Authentication Artifacts: Scrapes saved browser credentials, active session tokens, and stored two-factor authentication (2FA) recovery codes associated with the webmail instance.
Persistent MFA Bypass via Legacy Passcodes
One of the key capabilities embedded within the Ulej framework is its method for establishing persistent access. Recognizing that active webmail sessions expire and user passwords are periodically changed, the script interacts with Zimbra’s account settings to silently generate a new Zimbra Application Passcode. These application tokens are designed to support legacy mail protocols, such as IMAP, POP3, and ActiveSync, which do not natively support modern multi-factor authentication (MFA) workflows like Time-based One-Time Passwords (TOTP).
By issuing and exfiltrating a valid application passcode back to Laundry Bear infrastructure, the threat actors secure an out-of-band backchannel to the user’s mailbox. Even if the victim notices suspicious activity, changes their primary password, and terminates all active browser sessions, the generated application passcode remains valid. The adversary can continue synchronizing mail through external IMAP/ActiveSync clients, completely bypassing MFA checks indefinitely.
Dual-Channel Exfiltration Architecture
To maximize operational stealth and circumvent standard Data Loss Prevention (DLP) gateways, Ulej employs a dual exfiltration topology managed by the group’s back-end Flowerbed collection infrastructure, typically hosted on unattributable Virtual Private Servers (VPS):
- Low-Bandwidth DNS Tunneling: Metadata, small system artifacts, harvested credentials, and generated application tokens are obfuscated, base64-encoded, and transmitted via outbound DNS A-record queries targeting adversary-controlled authoritative name servers. This technique blends into legitimate enterprise DNS traffic.
- Encrypted HTTPS Uploads: Large data archives—such as compressed mailbox folders and complete address lists—are staged locally in memory, compressed, and uploaded over outbound HTTPS endpoints directly to Flowerbed command-and-control (C2) servers.
Comprehensive Threat Mitigation and Enterprise Remediation
Neutralizing the threat posed by Laundry Bear requires a multi-layered response. Security operations centers (SOCs) and system administrators must recognize that simply applying software patches is insufficient to clear an active intrusion. Patching closes the zero-click vulnerability window but does nothing to invalidate application passcodes, session tokens, or credentials that have already been harvested by the Ulej payload.
Organizations utilizing Zimbra Collaboration Suite must execute the following comprehensive remediation protocol:
- Apply Emergency Software Updates: Upgrade all on-premises ZCS servers immediately to ZCS versions 10.0.18, 10.1.13, or newer. Upgrading remediates CVE-2025-66376 by patching the CSS
@importsanitization flaw within the Classic UI. - Revoke Application Passcodes and Tokens: Query the Zimbra LDAP directory or administration console to identify, audit, and revoke all active application passcodes across the organization. Any application passcode generated without explicit user justification should be treated as an indicator of compromise (IOC).
- Enforce Global Credential and Session Resets: Force an immediate password reset for all webmail users and terminate all active user sessions across the ZCS cluster to invalidate stolen session cookies.
- Disable Legacy Mail Protocols: Where feasible, disable legacy IMAP and ActiveSync protocols at the server level, or restrict access to mandatory VPN corridors to prevent unauthenticated out-of-band mailbox synchronization.
- Inspect Network and DNS Logs: Hunt for anomalous, high-frequency outbound DNS A-record queries containing long encoded subdomains, as well as unusual outbound HTTPS connections originating from webmail servers to unfamiliar external IP addresses.
As nation-state threat actors like Laundry Bear continue to weaponize zero-click webmail vulnerabilities, security leaders must shift toward proactive threat hunting and continuous authentication validation. Defending critical infrastructure in an era of silent exploitation demands not only timely patch management, but also rigorous monitoring of session persistence mechanisms that adversaries exploit to quietly maintain operational control.
Written by
TempMail Ninja
Digital privacy and online security expert. Passionate about creating tools that protect users' identity on the internet.


