Wire flash
TechUS, Allies Warn Russian Hackers Exploit Zero-Click Zimbra Bug to Steal Government Emails
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
U.S. and allied cyber-intelligence authorities warned that Russian state-backed hackers, known as Laundry Bear, have exploited a vulnerability in the Zimbra Collaboration Suite to steal emails, passwords, and two-factor authentication tokens from over 10 Western organizations since July 2025. The campaign is notable for using a 'zero-click' or 'half-click' exploit that activates when a victim simply opens or previews a malicious email, without needing to click a link or download an attachment. Targets include defense contractors, federal and local governments, law enforcement, technology firms, educational institutions, media outlets, and NGOs. The hackers used attacker-controlled Proton Mail accounts and compromised addresses to send emails, embedding malicious code directly in the message body. CISA, NSA, FBI, and agencies from Australia, Canada, New Zealand, the UK, and over a dozen European countries jointly issued the advisory, urging organizations to patch Zimbra software and monitor for suspicious activity.
Source report
U.S. and allied cyber-intelligence authorities warned Thursday that Russian state-backed hackers have exploited a vulnerability in widely used email software to steal messages, passwords, and authentication data from Western government agencies and other organizations.
Zero-Click Exploit
The campaign is notable because it does not require victims to click a malicious link or download an attachment. According to a joint advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the FBI, the exploit can activate when someone simply opens or previews an email in an unpatched version of the Zimbra Collaboration Suite — a popular alternative to major collaborative messaging platforms like Microsoft Exchange or Google Workspace.
Targeting and Impact
The Russian hacking group, known primarily as Laundry Bear, has successfully targeted more than 10 organizations since July 2025, the agencies said. The campaign has affected:
- Defense industrial base
- Federal and local governments
- Law enforcement
- Technology companies
- Educational institutions
- Media outlets
- Nongovernmental organizations
The hackers sought to steal email addresses, passwords, and two-factor authentication tokens, which could allow them to retain access to compromised accounts even after obtaining a victim's password. Their tools also attempted to collect an organization's email directory, as much as 90 days of a victim's communications, and other sensitive information.
Related Government Procurement
The Treasury Department's Financial Crimes Enforcement Network (FinCEN) purchased a Zimbra standard support subscription in February 2025, according to federal contracting data listed in GovTribe, a federal market intelligence platform owned by Nextgov/FCW parent company GovExec. The purchase does not indicate whether FinCEN used the vulnerable version of the software or was targeted in the campaign.
Technical Details
"Unlike traditional phishing that attempts to persuade a user to take an action, such as clicking a link or downloading a file, Laundry Bear's current campaign uses a zero-click exploit that only requires a user to view a malicious email," CISA said in a statement.
Proofpoint, which also investigated the activity, describes the technique as a "half-click" exploit because the victim must still open or preview the email. The company said no additional interaction is required once the message appears in a vulnerable Zimbra webmail client.
The emails were sent from both attacker-controlled Proton Mail accounts and addresses that had already been compromised, according to Proofpoint.
In one example released by the company, the sender claimed to represent a Belgian media-verification organization and proposed cooperation among European institutions combating disinformation. The message contained a legitimate-looking link to a European Union events calendar, but the malicious code was embedded directly in the email itself.
Recommendations
CISA urged organizations to:
- Update all Zimbra mail software
- Monitor their email systems for suspicious activity
- Review the technical indicators included in the advisory
Organizations that find evidence of a compromise should follow the agencies' remediation guidance rather than relying solely on installing the available patch.
"CISA continues to see sophisticated and less sophisticated nation-state cyber groups deploy increasingly novel exploits into a highly successful capability to disrupt critical infrastructure or conduct espionage," said Chris Butera, CISA's acting executive assistant director for cybersecurity.
International Coordination
The advisory was also backed by defense, cybersecurity, and intelligence agencies from Australia, Canada, New Zealand, the United Kingdom, and more than a dozen European countries.
Source
Government Executive - All ContentWestern
Part of this Story
Russian Hackers Steal Government Emails via Zero-Click Zimbra Exploit, Cyber Agencies Warn