Particle.news
Download on the App Store

U.S. and Allies Attribute Long‑Running Zimbra Mail Theft to Russian Group Laundry Bear

Agencies say the campaign is a state‑backed espionage effort, with patches unable to undo credentials and app passwords already taken

Overview

  • A 31‑page joint advisory published July 23, 2026, named Laundry Bear as the actor that used a stored XSS flaw in Zimbra Classic to steal mail and account data without users clicking links.
  • The exploited bug, tracked as CVE‑2025‑66376, allowed JavaScript in an email to run when a message was viewed and exfiltrate up to 90 days of mail, saved passwords, the global address list and two‑factor recovery codes.
  • Attackers also created app‑specific passcodes and used AiTM phishing and attacker‑controlled ProtonMail accounts to harvest session cookies and retain access even after password resets.
  • Zimbra patched the Classic UI in November 2025 but agencies and vendors warn that unpatched servers and already compromised accounts remain the principal risk and require account reviews and revocation of unauthorized app passwords.
  • Authorities and vendors released indicators of compromise, detection rules and step‑by‑step remediation guidance, and they urged organizations to monitor authentications, block listed domains and update Zimbra to supported releases.