U.S. authorities warned in an advisory released Thursday that a state-sponsored threat actor has targeted government and private sector organizations since mid-2025 through a sophisticated phishing campaign that exploits a high-severity flaw in Zimbra Collaboration Suite.
A Russia-backed threat actor known as Laundry Bear targeted cloud environments in Ukraine before expanding to Western targets in various industrial sectors, according to the Cybersecurity and Infrastructure Security Agency and National Security Agency.
After initially focusing on Microsoft Exchange environments, the hacker targeted a zero-day flaw in Zimbra, tracked as CVE-2025-66376, beginning around May 2025.
The flaw allows an attacker to execute a Javascript payload due to improper sanitation of Cascading Style Sheets’ import directives. The CVE was not published until January 2026, meaning the exploitation continued for months as a zero-day.
The exploit allows an attacker to steal up to 90 days of email, the users’ global address list and other sensitive information, according to the advisory. The exploit also allows an attacker to gain persistent access to an environment.
Authorities said users should immediately patch their systems. If immediate patching is not possible, they should switch to another email client.