← Knowledge Center
Zero-Day

Russian APT LAUNDRY BEAR Exploits Zimbra Zero-Day in Phishing Campaign

CISA has issued an advisory detailing a campaign by a Russian state-supported APT group tracked as LAUNDRY BEAR that has targeted Western government and commercial organizations using Zimbra Collaboration Suite since at least July 2025. The group’s objective is the covert collection of sensitive email data on behalf of the Russian Federation, delivered via a phishing campaign that leverages a novel exploit which was a zero-day at the time of first use.

What stands out from an identity standpoint is LAUNDRY BEAR’s reliance on credential-focused and access-abuse techniques. Prior campaigns have used password spraying, phishing, and pass-the-cookie attacks—the latter allowing session hijacking that bypasses password and MFA prompts entirely—enabling high-volume operations without sophisticated tooling.

What to take away: Organizations running Zimbra should patch promptly and treat session tokens and cached cookies as sensitive credentials. Defending against these actors requires hardening authentication against spraying, monitoring for anomalous session reuse, and enforcing session invalidation on suspicious activity.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.