bleeping-computer · Crawled Jul 23, 2026

Russian hackers exploit Zimbra zero-click flaw for email theft

6 IoCs 1 Actors 1 CVEs
Read original article ↗

AI Summary

Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting a patched zero-click XSS vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite to steal email data, including credentials, 2FA tokens, and the Global Address List. The group targets organizations in the Defense Industrial Base, government, education, energy, and technology sectors, using both the vulnerability and adversary-in-the-middle phishing kits to bypass MFA and maintain persistent access. Stolen data is exfiltrated via DNS and HTTPS to attacker-controlled infrastructure using the 'Flowerbed' collection framework.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 6 extracted

Type Value Detail
Domain mailnalysis[.]com Details →
Domain emailanalytics[.]com[.]ua Details →
Domain zimbrastat[.]com Details →
Domain zimbra-metadata[.]com Details →
Domain istc-cloud[.]com Details →
Domain zmailanalytics[.]com Details →

MITRE ATT&CK TTPs 23 techniques