THREAT SUMMARY
CISA Alert Code: AA26-204A
Release Date: July 23, 2026
Threat Category: Russian State-Supported Cyber Espionage
Threat Actor: LAUNDRY BEAR
Additional Tracking Names: Void Blizzard, CL-STA-1114, TA488, formerly UNK_PitStop
Affected Product: Zimbra Collaboration Suite Webmail
Vulnerability: CVE-2025-66376
Weakness: CWE-79 — Improper Neutralization of Input During Web Page Generation
Primary Risks: Email theft, credential theft, authentication-token theft, directory harvesting, persistent mailbox access and cyberespionage
Threat Status: Actively exploited in an ongoing campaign
Affected Environments: Government, defense, energy, education, law enforcement, media, technology and nongovernmental organizations
Attack Vector: Malicious email viewed through a vulnerable Zimbra webmail client
User Interaction Required: Viewing the malicious email; no link click or attachment opening is required
Patched Versions: ZCS 10.1.13 and ZCS 10.0.18
CISA Action: Patch immediately, inspect for compromise, revoke exposed authentication data and monitor Zimbra and network activity
The Cybersecurity and Infrastructure Security Agency and a broad coalition of American and international security agencies are warning that Russian state-supported cyber actors have been compromising Western government and commercial organizations through a dangerous vulnerability in the Zimbra Collaboration Suite.
The campaign has been active since at least July 2025 and is attributed to an advanced persistent threat group primarily tracked as LAUNDRY BEAR. Cybersecurity organizations also track related activity under the names Void Blizzard, CL-STA-1114 and TA488, formerly UNK_PitStop.
CISA assessed that LAUNDRY BEAR is conducting the campaign to covertly acquire sensitive email communications and other information for the Russian Federation. The absence of known financial extortion, the persistent collection of government and organizational communications and the group’s targeted victim selection strongly support an espionage objective.
The campaign exploits CVE-2025-66376, a cross-site scripting vulnerability caused by improper sanitization of Cascading Style Sheet @import directives inside an email. The flaw allows malicious JavaScript embedded in an email to execute when the message is viewed through a vulnerable Zimbra webmail client.
This is not a traditional phishing operation requiring a victim to select a link, open an attachment or provide credentials through a fraudulent login page. The malicious code can begin executing when the targeted user views the email.
The vulnerability was being exploited months before it was publicly disclosed and before a security update became available, making it a zero-day vulnerability during the opening phase of the campaign. Synacor released patches in November 2025, and the National Vulnerability Database published CVE-2025-66376 on January 5, 2026. CISA confirmed that the flaw continues to be successfully exploited against organizations that have not updated their Zimbra installations.
The malicious capability used in the campaign is named Ulej, written as “Улей” in Russian and translated as “beehive.” Ulej was custom-developed to exploit vulnerable Zimbra webmail sessions, collect information directly from victim accounts and transfer it to infrastructure controlled by LAUNDRY BEAR.
The exploit hides a Base64-encoded JavaScript payload inside the onload field of a Scalable Vector Graphics element. The final script is XOR-encrypted and contained inside another Base64-encoded payload. The outer code decodes and decrypts the inner payload before executing the collection and exfiltration functions.
LAUNDRY BEAR can alter the XOR encryption key or add nonfunctional @import directives to produce modified payloads capable of evading basic signature-based detection. CISA stated that the use of a previously unknown vulnerability demonstrates the group’s ability to operationalize novel exploits despite indications that parts of its supporting infrastructure were built using basic code, open-source tools and artificial intelligence assistance.
Once executed, Ulej attempts to collect and exfiltrate a significant amount of sensitive information from the victim’s account. The targeted data includes the previous 90 days of email communications, the victim’s email address, Zimbra version information, the address of the webmail page at the time of exploitation, the organization’s Global Address List, two-factor authentication scratch codes, OAuth consumer information, device status, saved passwords supplied through browser or password-manager autocomplete and a newly created application-specific password.
The script performs its collection process through 12 asynchronous stages:
sendStartPinggather_emailgather_environmentgather_2fa_codesgather_app_passwordgather_device_statusgather_oauth_consumersgather_autocomplete_passwordenable_mail_protocolsgather_galsendArchivessendFinishPing
Ulej attempts to obtain the victim’s Cross-Site Request Forgery token from the webmail page’s local storage. If successful, the script uses Zimbra Simple Object Access Protocol requests to query the account, modify preferences and gather authentication information.
During the password-collection stage, the script inserts concealed username and password fields outside the victim’s visible browser area. It then waits to determine whether a password manager or browser autocomplete function supplies saved credentials to those fields. If a credential is entered automatically, the script attempts to capture and exfiltrate it.
The malicious code also tries to enable Internet Message Access Protocol access to the compromised mailbox. CISA assessed that LAUNDRY BEAR almost certainly uses an external IMAP-compatible email client to maintain access to victim communications.
Because some IMAP clients do not support Zimbra’s normal two-factor authentication process, Zimbra allows users to create application-specific passcodes. Ulej abuses this feature by generating a new application passcode named ZimbraWeb. The attacker can then use that passcode to access the mailbox without completing the victim’s regular two-factor authentication process.
CISA stated that an application passcode named ZimbraWeb is almost certainly malicious in the context of this campaign. Zimbra webmail supports two-factor authentication directly and has no legitimate need for an application passcode carrying that name.
The script separately attempts to retrieve two-factor authentication scratch codes through the GetScratchCodesRequest SOAP command. Each code recovered through this process can be transferred individually to the attackers.
Ulej attempts to harvest email messages from the 90 days preceding exploitation while excluding messages marked as junk. It queries each day separately and stores markers in the browser’s local storage using the format zd_comp_YYYY-MM-DD. These markers prevent the script from repeatedly collecting the same dates if it executes again from the same device. Messages sent or received on the day of execution are always targeted.
The presence of zd_comp_YYYY-MM-DD entries in local storage can help defenders identify affected users and determine which dates of email communications may have been stolen.
The script attempts to gather the organization’s Global Address List through a large series of searches covering two-character combinations constructed from letters, numbers, periods, hyphens and underscores. This behavior produces a substantial volume of SearchGalRequest activity that can be identified in Zimbra logs.
Collected information is transferred through Domain Name System queries and encrypted HTTPS connections. Ulej uses randomized victim identifiers and encodes smaller datasets into DNS queries directed toward actor-controlled domains. Larger collections, including archived email data, are transmitted through HTTPS.
The operation’s server-side collection system is known as Flowerbed. It is a Python project deployed through Docker containers named Catcher, Certbot, Nginx and Gardener.
Catcher receives and organizes data transferred through DNS and HTTP. Certbot generates Let’s Encrypt certificates through Cloudflare DNS challenges. Nginx operates as an HTTPS reverse proxy, allowing stolen information to travel through an encrypted channel. Gardener checks whether the Catcher service is operating correctly.
The Nginx configuration validates whether the Server Name Indicator contains the pattern *.i.* before forwarding traffic to Catcher. Connections that do not contain the expected value receive a 444 response, a measure likely intended to reject unrelated traffic and reduce outside observation of the infrastructure.
LAUNDRY BEAR provisions virtual private servers through several providers, at times using fabricated identities despite Know Your Customer requirements. The actors primarily use Mullvad VPN when administering the infrastructure. Individual servers are normally retained for periods ranging from seven to 60 days before the operation moves to new systems.
CISA reported that data received by Flowerbed is temporarily stored in /root/hits/tmp and transferred to /root/hits/ready after processing. An automated process establishes brief Secure Shell connections approximately every 60 seconds, almost certainly moving the stolen information from the public collection server to private infrastructure controlled by the actors.
The group has targeted and compromised users associated with the defense industrial base, federal and local government, education, energy, law enforcement, media, nongovernmental organizations and technology companies.
Earlier LAUNDRY BEAR operations relied on password spraying, stolen credentials, phishing, session-cookie theft and adversary-in-the-middle techniques. In one documented operation, the actors created a fraudulent website resembling a European defense and security conference registration portal. Credentials and session tokens entered through that site were intercepted using a modified version of Evilginx and used to access email accounts.
The shift to a view-based Zimbra exploit gives the group a more covert method of compromising accounts. Since at least November 2025, LAUNDRY BEAR has also distributed malicious emails through accounts belonging to earlier victims, allowing the messages to originate from legitimate but compromised infrastructure.
CISA identified the following domains and IP addresses as historical Flowerbed infrastructure associated with the campaign:
zmailanalytics[.]com—216.252.238[.]104zimbra-metadata[.]com—216.252.238[.]18analyticemailmeter[.]com—37.120.247[.]228emailanalytics.com[.]ua—185.86.79[.]95mailnalysis[.]com—104.248.134[.]194zimbrastat[.]com—64.226.124[.]190zimbrasoft.com[.]ua—193.238.152[.]66synacorzimbra[.]nl—216.252.238[.]64istc-cloud[.]com—194.156.103[.]193
CISA cautioned that LAUNDRY BEAR frequently changes its operational infrastructure. Domains, email addresses and IP addresses contained in the advisory may no longer be active and should be treated as historical attribution indicators. Organizations should confirm current activity before blocking shared infrastructure or taking action based solely on an individual indicator.
Email addresses associated with procurement of infrastructure include:
ivanka.zurabishvili@proton[.]mezmul1@buildandconsulting[.]comgarrysmithme@pinmx[.]nethostingclient@pinmx[.]net
Addresses and domains associated with malicious-email distribution include:
c.laurent.ejfa@proton[.]mej.moreau.epsc@proton[.]meliberty.insights@proton[.]me- Suspected compromised addresses ending in
@isofts.kiev[.]ua - Suspected compromised addresses ending in
@navs.edu[.]ua
CISA supplied the following SHA-256 hashes for email samples containing malicious payloads associated with the campaign:
98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760
Administrators should review /opt/zimbra/log/mailbox.log for abnormal SOAP activity. High-risk behavior includes numerous SearchGalRequest commands issued by one user during a short period, creation of an application passcode through CreateAppSpecificPasswordRequest, creation of a passcode named ZimbraWeb and use of GetScratchCodesRequest.
Network monitoring should identify frequent DNS requests involving suspicious domains and randomized subdomains, sudden connections to newly registered infrastructure, large outbound transfers to virtual private server providers not used by the organization and access to internal email systems from Mullvad VPN or other unexpected VPN services.
Organizations capable of inspecting outbound HTTPS traffic should search for encrypted connections and transfer patterns matching Ulej’s exfiltration behavior. Packet captures, NetFlow records, DNS logs, proxy records, authentication data, endpoint telemetry and Zimbra application logs should be retained long enough to support investigation and determine the full scope of a compromise.
Every organization operating Zimbra Collaboration Suite should immediately confirm that it is not running a version vulnerable to CVE-2025-66376. Security updates were released for ZCS 10.1.13 and ZCS 10.0.18. Administrators should apply the appropriate patched release without delay.
If immediate patching is impossible, employees should access email through an alternative client and avoid the Classic Zimbra webmail client until the installation has been updated to a non-vulnerable version.
Organizations should consider placing a third-party authentication service supporting passkeys in front of Zimbra and other services that do not provide native passkey support. This can reduce exposure to automated password collection and reused credentials. Application-specific passcodes may still be required for some clients and must be closely monitored.
Discovery of a malicious message exploiting CVE-2025-66376 should trigger an immediate search for messages with matching content, sender information and subject lines. Related messages should be quarantined to prevent additional users from viewing them and activating the exploit.
An organization that identifies activity connected with this campaign should determine which users were affected and record the dates of suspected compromise. Investigators should use the local-storage markers, email archives, SOAP requests, network traffic and published indicators to establish which communications and credentials may have been exposed.
All application-specific passcodes and two-factor authentication scratch keys should be revoked across the affected organization. Employees should be required to create new, unique passwords that meet established strength requirements. CISA warned that compromised users may have had any password automatically supplied by a browser or password manager stolen during exploitation, not only their Zimbra credential.
Patching closes the vulnerability but does not remove persistence already established through stolen passwords, session data, two-factor authentication scratch codes, newly generated application passcodes or enabled IMAP access. Organizations finding evidence of exploitation must complete credential revocation, mailbox investigation, endpoint review and network analysis in addition to installing the security update.
The advisory was jointly issued and sealed by the National Security Agency; Federal Bureau of Investigation; Netherlands Defence Intelligence and Security Service; Netherlands General Intelligence and Security Service; Cybersecurity and Infrastructure Security Agency; Defense Counterintelligence and Security Agency; Department of Defense Cyber Crime Center; Department of the Treasury; Naval Criminal Investigative Service; Australian Signals Directorate’s Australian Cyber Security Centre; Communications Security Establishment Canada’s Canadian Centre for Cyber Security; New Zealand National Cyber Security Centre; United Kingdom National Cyber Security Centre; Czech Republic National Cyber and Information Security Agency; Danish Defence Intelligence Service; Estonian Foreign Intelligence Service; Finnish Defence Intelligence; Finnish Security and Intelligence Service; French General Directorate for Internal Security; French National Cybersecurity Agency; Italian External Intelligence and Security Agency; Italian Internal Intelligence and Security Agency; Security and Intelligence Service of the Republic of Moldova; Polish Foreign Intelligence Agency; Military Counterintelligence Service of Poland; Spain National Intelligence Centre; and Sweden National Cyber Security Centre.
The participating agencies assessed that LAUNDRY BEAR may discontinue this specific exploitation method as more organizations install the Zimbra updates. Based on the success of this and earlier operations, the group is very likely to continue targeting Zimbra and other email systems used by organizations in Western countries. Future campaigns are expected to continue using email, newly discovered vulnerabilities and social-engineering methods to obtain sensitive communications for Russian state intelligence purposes.
Forecast — 30 Days
- Accelerated scanning for exposed Zimbra systems: Russian state-supported actors and other threat groups are expected to identify organizations that remain on versions vulnerable to CVE-2025-66376.
- Continued exploitation of unpatched installations: Viewing a malicious email through a vulnerable Zimbra webmail client is sufficient to activate the exploit, leaving delayed patching as the most immediate source of additional compromises.
- Migration to replacement infrastructure: Published domains and IP addresses will lose detection value as LAUNDRY BEAR rotates virtual private servers, certificates, email accounts and exfiltration domains.
- Reuse of compromised mailboxes: Previously breached accounts are likely to remain part of the campaign’s distribution network, allowing malicious messages to originate from recognized organizations and trusted contacts.
- Expanded credential abuse: Stolen passwords, application passcodes, two-factor authentication scratch codes and enabled IMAP access may support continued mailbox entry after vulnerable systems are patched.
- Targeting beyond the current Zimbra exploit: LAUNDRY BEAR is very likely to continue pursuing government, defense, energy, law enforcement, education, media and technology organizations through Zimbra or other email platforms.
- Growth in threat hunting and compromise assessments: Organizations responding to AA26-204A will likely uncover earlier email theft and persistent account access that remained undetected because the exploit required no link click or attachment opening.
TRJ Verdict
This campaign is not a routine phishing operation and should not be treated as a standard patching notice. Russian state-supported cyber actors turned a previously unknown Zimbra vulnerability into a low-interaction espionage capability capable of stealing 90 days of email, organizational directory information, saved passwords, authentication codes and persistent mailbox credentials when a victim viewed a malicious message.
Installing the Zimbra update is necessary, but patching alone cannot remove access already established through stolen credentials, application passcodes, two-factor authentication scratch keys, active sessions or enabled IMAP connections. Organizations must investigate historical activity, revoke authentication material, reset potentially exposed passwords and determine which communications were exfiltrated.
The most serious risk is not limited to the original compromised mailbox. Stolen communications and address-book data can support additional targeting, impersonation, intelligence collection and attacks against trusted partners. Every vulnerable Zimbra installation should be treated as an immediate operational security concern, and every confirmed indicator should trigger a full compromise assessment—not a patch-only response.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



