Overview
- U.S., NSA, CISA and more than a dozen international partners published a joint advisory on July 23–24 attributing a year‑long campaign against Zimbra to the Russian state‑linked group known as Laundry Bear.
- The attackers exploited a stored cross‑site scripting bug (CVE‑2025‑66376) in Zimbra’s Classic webmail so that simply viewing or previewing a message ran attacker JavaScript inside an authenticated session.
- Operators used a custom payload and collection framework to steal up to 90 days of mail, saved passwords, two‑factor recovery codes and to create persistent app‑specific passcodes such as “ZimbraWeb” that can bypass normal TOTP flows.
- Agencies released indicators of compromise and step‑by‑step remediation guidance that tells organizations to update Zimbra, revoke unauthorized app passwords, reset affected accounts and hunt for the listed domains and logs.
- The advisory says the campaign was tested heavily against Ukrainian targets before spreading to U.S. and NATO‑aligned organizations and that recent U.S. legal filings link the activity to Yutek‑NN and an accused individual, Denis Obrezko.