Russian spies exploit unpatched Zimbra flaw to steal NATO member emails – zero clicks required
Hackers quietly tested the zero-click tactic in Ukraine before targeting NATO member organizations, CISA says.

Image by Cybernews
- Russian spies exploited an unpatched Zimbra zero-day to steal emails from organizations in NATO member countries – no clicks required.
- The campaign began in Ukraine before expanding to Western government and commercial targets, according to CISA and its partners.
- CISA warns many organizations still haven't patched the flaw, leaving vulnerable email servers exposed to future attacks.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A Russian threat actor is actively exploiting an unpatched Zimbra zero-day – requiring absolutely no user clicks – to steal emails from an untold number of Western organizations in NATO member countries, according to a joint CISA advisory issued Thursday.
A nation-state threat group researchers have dubbed Laundry Bear is being blamed for the Putin-backed campaign, according to the international advisory.
The campaign is exploiting a critical vulnerability in the Zimbra Collaboration Suite (ZCS) – a business collaboration platform similar to Microsoft Exchange or Google Workspace – allowing attackers to compromise email accounts simply by sending a specially crafted email and requiring no user interaction.
Users do not have to click a link, open an attachment, or even enter their passwords to fall victim to the espionage attack – triggering alerts from cyber watchdog partner agencies across the globe, including in the UK, Canada, Australia, Italy, Spain, France, Finland, the Czech Republic, Poland, and the Netherlands.
The vulnerability, listed as Common Vulnerabilities and Exposures (CVE) CVE-2025-66376, was patched in November 2025.
Still, the US Cybersecurity and Infrastructure Security Agency (CISA), along with the NSA, FBI, DCSA, DC3, NCIS, and the US Treasury Department, warns that many organizations have yet to patch the flaw, leaving internet-facing Zimbra servers at risk of continued exploitation.
It’s estimated that the Zimbra platform powers more than 200 million mailboxes across more than 140 countries, including an estimated 3,000 “highly regulated global institutions” in the US alone, ranging from government bodies to educational entities, CISA said.
Laundry Bear turns from Ukraine to the West
Authorities say the hackers aim to gather sensitive intelligence for the Russian Federation, primarily focusing on the covert acquisition of email data.
The victims span multiple sectors, including government, defense, technology, and other organizations of strategic interest.
What’s more, it appears Laundry Bear first began testing its zero-click methods on organizations in Ukraine before expanding the campaign to target government and commercial organizations across NATO member countries.
“Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques – including password spraying, phishing, and pass-the-cookie – allowing the group to successfully run high-volume operations,”CISA states.
Russia had been observed targeting the Zimbra productivity suite since at least July 2025. Other industry labels for the nation-state actors include Void Blizzard, CL-STA-1114, and TA488 (formerly UNK_PitStop).
Zero-click attack leaves little for victims to do
The campaign – also referred to as “half-click” or “zero-click” by security researchers – requires virtually no interaction from victims, unlike traditional phishing attacks.
Simply viewing a malicious email in a vulnerable Zimbra webmail client is enough to trigger the exploit and compromise the user’s mailbox.
Once inside, the attackers deployed custom malware designed to harvest emails and maintain persistent access to compromised accounts.
“The exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR,”the advisory warns.
Unpatched servers remain at risk
The advisory provides a list of mitigation techniques and indicators of compromise (IOCs) for organizations running Zimbra.
Defenders are urged to immediately install available security updates, review systems for indicators of compromise, and investigate any suspicious activity associated with the campaign.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Based on Laundry Bear’s previous espionage campaigns, the advisory warns that unpatched internet-facing Zimbra servers will likely remain an attractive target for Russian intelligence operations.
“The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their effort,” CISA said.
Has your password leaked?