Particle.news
Download on the App Store

U.S. and Allies Attribute Year‑Long Zimbra Email Theft to Russian Group Laundry Bear

A joint advisory warns the Zimbra zero‑day let attackers steal 90 days of email and account credentials simply by viewing messages, leaving unpatched servers at ongoing risk.

Overview

  • On Thursday, July 23, 2026, U.S. and more than a dozen allied agencies issued a 31‑page advisory publicly blaming the Russian government‑supported group Laundry Bear for a sustained espionage campaign that began in mid‑2025.
  • The attackers exploited a Zimbra Collaboration Suite vulnerability (CVE‑2025‑66376) that ran JavaScript when a user viewed an email, allowing no‑click theft of the previous 90 days of mail, passwords, address books, search history and two‑factor tokens.
  • U.S. authorities tied the operation to the Russian firm Yutek‑NN and an indictment this month names Yutek‑NN deputy director Denis Obrezko, who faces hacking charges in Boston following his arrest in Thailand.
  • Officials released technical indicators and step‑by‑step mitigation guidance and urged organizations to update Zimbra, revoke unauthorized application passcodes, monitor logins and adopt phishing‑resistant multi‑factor authentication.
  • Security firms and officials said the group tested the technique on Ukrainian targets before wider deployment and used tools such as a custom JavaScript payload and a data‑aggregation framework called 'beehive,' which raises the risk the methods could be reused against other vulnerabilities.