Lubos Chlubny - stock.adobe.com
Russian APT Laundry Bear perfects zero-click phishing attack
A newly identified Russian state threat actor is using a novel zero-click phishing technique, likely developed with the help of an AI, to target Western users of Zimbra software products
An emerging threat actor linked with confidence to the Russian state is targeting Western organisations with a novel zero-click phishing attack technique designed to compromise email platforms and gain persistent access to its target networks.
Flagged by the UK’s National Cyber Security Centre (NCSC), alongside its Five Eyes partners and sister agencies from across Europe, the new operation has been given the name Laundry Bear, and has successfully stolen sensitive data from multiple targets in sectors such as defence, education, energy, government, law enforcement, media and non-governmental organisations (NGOs).
The advanced persistent threat (APT) group has likely been around since 2024, and has developed a zero-click exploit termed beehive or Ulej that specifically targets Zimbra Collaboration Suite (ZCS) software. The NCSC said this technique was initially tested against Ukrainian targets prior to being turned against Western organisations, which is “indicative of espionage” and means Laundry Bear is “almost certainly” acting with Moscow’s support.
“This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organisations,” said NCSC chief operating officer Beth Hopkins.
“With our international partners, we strongly encourage organisations to familiarise themselves with the zero-click techniques described in the advisory which could be used against other platforms, and act on the mitigation advice.
“We will continue to call out malicious cyber activity supported by the Russian state and urge everyone to follow NCSC guidance to raise resilience, including steps to strengthen online account security.”
Busy bees
The background to Laundry Bear’s campaign dates back to May 2025 when the Dutch authorities warned of a cluster of malicious activity targeting Microsoft Exchange and abusing legitimate application programming interfaces (APIs) to exfiltrate bulk data. At this stage ,the group appeared to be using a malicious website masquerading as a European Defence and Security Summit registration portal.
However, from around July 2025, Laundry Bear shifted to a far more technical phishing method with its custom-developed beehive technique – technical analysis conducted by the NCSC suggests that artificial intelligence (AI) tools were used in the generation of a simple codebase for this purpose.
Unlike the Microsoft campaign, beehive enables Laundry Bear to gain sustained access to its target’s emails with no input from the user. More usually, a victim must click a link or open a file to enable this kind of access but in this instance, they only have to view a malicious email within a vulnerable version of ZCS’ webmail service in order to be compromised.
Beehive specifically targets a flaw tracked as CVE-2025-66376, a stored cross-site-scripting (XSS) vulnerability in ZCS’ classic user interface that allows attackers to abuse cascading style sheets (CSS) @import directives in email HTML.
Zimbra patched this flaw in November 2025 and the NCSC is urging any users that have not updated to immediately patch it and conduct urgent network monitoring.
The NCSC warned that while CVE-2025-66376 specifically exists in ZCS, the beehive technique itself could be readily adapted to exploit other vulnerabilities. It added that as more organisations update their ZCS instances, Laundry Bear would very likely look to target other email systems as the pool of potential victims empties out.
Huntress senior manager of security operations Dray Agha said: “These exploits are a worst-case scenario for defenders because it is a zero-click attack, meaning simply viewing the email in a vulnerable client triggers the compromise. This completely bypasses traditional employee security training and gives state-backed hackers a silent, invisible backdoor into sensitive communications without the victim ever making a mistake.
“This is why defence-in-depth is advised, as where the human security layer is porous, the technical defensive layer can step in. Organisations shouldn’t just longer rely on their staff acting as a human firewall. Rapid software patching, coupled with layered technical defences, is the only reliable safety net against modern state-sponsored threats.”
Read more about phishing
- To combat phishing, Singapore's Singpass is launching a passwordless feature for iPhone users with a device-bound model to avoid the security risks of cloud-synced passkeys.
- With AI now powering the majority of phishing campaigns and attacks expanding beyond email into Teams, calendars and AI tools, security leaders across the Gulf are rethinking trust models.
- Deepfake phishing attacks are on the rise, as attackers use AI to deceive and defraud end users and their employers. Learn what CISOs can do to protect their organisations.
