Laundry Bear Uses Zero-Click Zimbra Email Trap

Computer Weekly Security · High sophistication
Last updated July 30, 2026

A newly identified Russia-linked threat actor (“Laundry Bear”) is targeting Western organisations with a zero-click technique that can compromise Zimbra webmail simply by viewing a malicious email. The campaign has reportedly stolen sensitive data across multiple sectors and may evolve to target other email platforms as organisations patch.

How the attack worked

Laundry Bear, a threat actor linked with confidence to the Russian state, has been targeting Western organisations since at least 2024. Its most notable technique, called beehive or Ulej, is a zero-click phishing method aimed at Zimbra Collaboration Suite (ZCS) webmail. Rather than relying on a victim clicking a malicious link, the technique exploits CVE-2025-66376, a stored cross-site-scripting vulnerability in the ZCS classic user interface. By abusing CSS @import directives embedded in HTML email content, an attacker can trigger compromise the moment a target simply views the email in a vulnerable webmail client.

Earlier activity attributed to the same group involved a different approach: a malicious website masquerading as a European Defence and Security Summit registration portal, used to lure targets in defence and government circles into submitting information through a fake registration flow.

Why it succeeded

The core reason this technique is effective is that it bypasses the standard advice given in most security awareness training. Employees are typically taught to avoid clicking suspicious links or opening unexpected attachments, but a zero-click exploit does not require any of that. Merely viewing an email in a vulnerable version of ZCS webmail is sufficient to trigger compromise, which sidesteps the usual human decision point that awareness training is designed to influence.

The technique also targeted a broad range of sectors, including government, defence, education, energy, law enforcement, media, and NGOs, giving it a wide potential impact across organisations that rely on Zimbra webmail.

What to watch for

  • Unexpected or unsolicited HTML-formatted emails, particularly ones with rich content that could load external resources
  • Emails viewed through an unpatched classic Zimbra web interface
  • Unexpected event invitations or registration requests tied to defence or government themes, especially where the site domain does not match the legitimate organiser
  • Pressure to register quickly or provide unusually sensitive information through unfamiliar portals

How to build resistance

Organisations should prioritize rapid patching of internet-facing email systems, since Zimbra patched this specific flaw in November 2025 and the NCSC has urged any unpatched users to update immediately. Layered technical defences matter because patching alone will not stop every variant of this kind of attack.

Security teams should also assume the beehive technique could be adapted to exploit other email platforms and vulnerabilities beyond Zimbra, so monitoring and response planning should not be limited to a single vendor. Finally, awareness programs should be updated to reflect that some attacks require no click at all, reinforcing the need for technical controls alongside training rather than relying on user behavior as the sole defense.

Key findings

  • Laundry Bear is linked “with confidence” to the Russian state and has targeted Western organisations since at least 2024.
  • The group used a “novel zero-click phishing” technique (“beehive” / “Ulej”) against Zimbra Collaboration Suite (ZCS) webmail, where “only have to view a malicious email” to be compromised.
  • Earlier activity included “a malicious website masquerading as a European Defence and Security Summit registration portal.”
  • Beehive targets CVE-2025-66376 (stored XSS) in ZCS classic UI by abusing “cascading style sheets (CSS) @import directives in email HTML.”
  • Zimbra patched the flaw in November 2025; NCSC urges rapid patching and monitoring, and warns the technique could be adapted to other platforms.

Who’s being targeted

  • Commonly targeted roles: All employees (especially Zimbra webmail users), Executive leadership, Government and defence teams, IT / Email administrators, Security operations (SOC).
  • Affected industries: Defence, Education, Energy, Government, Law enforcement, Media, Non-governmental organisations (NGOs).
  • Attack channels: website, email.
  • Impersonated: European Defence and Security Summit registration portal, Unknown / not specified (email content is weaponised rather than brand-led).

Red flags to watch for

  • Unexpected event invite/registration request tied to defence/government themes
  • Registration site domain or URL does not match the legitimate organiser
  • Pressure to register quickly or provide unusually sensitive information
  • Unusual/unsolicited HTML-formatted email
  • Email viewed in an unpatched “classic” Zimbra web interface
  • Unexpected rich content that could load external resources (e.g., CSS imports)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Laundry Bear zero-click attack?

It is a technique called beehive that exploits a stored cross-site-scripting flaw in Zimbra Collaboration Suite webmail, allowing compromise just from viewing a malicious HTML email.

Do victims need to click a link to be compromised?

No. Simply viewing the malicious email within a vulnerable version of ZCS webmail is enough to trigger compromise.

Has the Zimbra flaw been patched?

Yes, Zimbra patched the vulnerability, tracked as CVE-2025-66376, in November 2025, and the NCSC urges any unpatched users to update immediately.

Could this technique spread beyond Zimbra?

Yes, the underlying beehive technique could reportedly be adapted to exploit other vulnerabilities and email platforms.

Read the video transcript

You know that Zimbra webmail tab you leave open all day? Laundry Bear can hijack it just because you *look* at the wrong email. They’re running a zero-click attack called Beehive against Zimbra’s classic UI. Subject line looks normal, like “Updated meeting agenda, please review,” but the HTML hides a CSS @import trick for CVE-2025-66376. You don’t click anything, just viewing it can compromise your mailbox. Same group also spun up a fake European Defence and Security Summit registration site. The page screams “Register now for the European Defence and Security Summit,” but the URL is a random domain that doesn’t match any real organiser. Here’s the move: if you use Zimbra, don’t just avoid clicks, make sure your Zimbra is fully patched past the November 2025 fix, and report any odd HTML-heavy emails to security.

Similar attacks

Fake Claude Download Page Led to SectopRAT

Fake Claude Download Page Led to SectopRAT

Attackers abused Anthropic’s Claude “Artifacts” publishing feature to host a convincing fake Claude download page on the real claude.ai domain. Victims found…

July 23, 2026