CISA has issued an advisory detailing a campaign by a Russian state-supported APT group tracked as LAUNDRY BEAR that has targeted Western government and commercial organizations using Zimbra Collaboration Suite since at least July 2025. The group’s objective is the covert collection of sensitive email data on behalf of the Russian Federation, delivered via a phishing campaign that leverages a novel exploit which was a zero-day at the time of first use.
What stands out from an identity standpoint is LAUNDRY BEAR’s reliance on credential-focused and access-abuse techniques. Prior campaigns have used password spraying, phishing, and pass-the-cookie attacks—the latter allowing session hijacking that bypasses password and MFA prompts entirely—enabling high-volume operations without sophisticated tooling.
What to take away: Organizations running Zimbra should patch promptly and treat session tokens and cached cookies as sensitive credentials. Defending against these actors requires hardening authentication against spraying, monitoring for anomalous session reuse, and enforcing session invalidation on suspicious activity.