bleeping-computer · Crawled Jul 23, 2026
Russian hackers exploit Zimbra zero-click flaw for email theft
6 IoCs 1 Actors 1 CVEs
Read original article ↗
AI Summary
Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting a patched zero-click XSS vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite to steal email data, including credentials, 2FA tokens, and the Global Address List. The group targets organizations in the Defense Industrial Base, government, education, energy, and technology sectors, using both the vulnerability and adversary-in-the-middle phishing kits to bypass MFA and maintain persistent access. Stolen data is exfiltrated via DNS and HTTPS to attacker-controlled infrastructure using the 'Flowerbed' collection framework.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 6 extracted
MITRE ATT&CK TTPs 23 techniques
T1003.001 LSASS Memory · Credential Access T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1539 Steal Web Session Cookie · Credential Access T1557 Adversary-in-the-Middle · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access