Russian Phishing Campaign Targeting Zimbra Collaboration Suite

A joint international cybersecurity advisory and supplemental reporting detail a Russian state-sponsored espionage campaign conducted by a group known as LAUNDRY BEAR. Starting in mid-2025, these actors exploited a zero-day vulnerability in the Zimbra Collaboration Suite to infiltrate the email accounts of Western government and commercial entities. The attack utilized a view-based exploit, meaning users merely had to open a malicious email to trigger the unauthorised exfiltration of sensitive communications, contact lists, and authentication tokens. Beyond immediate data theft, the hackers established persistent access by manipulating account settings and generating secret application passwords to bypass multi-factor authentication. Security agencies and researchers urge immediate software updates and thorough account audits to mitigate these sophisticated technical threats. This ongoing activity underscores a strategic shift toward high-volume operations aimed at gathering long-term intelligence for the Russian Federation.