Russian Zero-Click Zimbra Exploit Steals Government Emails
Zimbra's smaller government footprint means fewer eyes on the logs, and this is the third zero-click nation-state email campaign in 18 months.
TL;DR
U.S. cyber agencies warned Thursday that Russian state-backed group Laundry Bear is exploiting a zero-click vulnerability in Zimbra Collaboration Suite that requires only that a victim open or preview a malicious email, no link click, no download. Active since July 2025, the campaign has hit more than 10 organizations across the defense industrial base, federal and local government, law enforcement, and other sectors. The exploit steals email archives up to 90 days, passwords, and two-factor authentication tokens. Zimbra's smaller government footprint compared with Exchange means these intrusions are less likely to be detected quickly.

The joint advisory from CISA, the NSA, and the FBI (backed by defense and intelligence agencies from Australia, Canada, New Zealand, the United Kingdom, and more than a dozen European countries) describes a campaign that's been running since at least July 2025 and has compromised more than 10 organizations. Unlike traditional phishing, Laundry Bear's current operation uses a zero-click exploit: the malicious code executes when a victim opens or previews an email in an unpatched Zimbra webmail client. Proofpoint, which also investigated the campaign, calls it a "half-click" exploit, since the victim must still interact with the message, but once the email appears on screen, no additional action is required.
The attackers have used both Proton Mail accounts they control and previously compromised addresses to deliver the malicious emails. In one example Proofpoint released, the sender posed as a Belgian media-verification organization proposing cooperation on disinformation. The message included a legitimate-looking link to an EU events calendar, but the payload was embedded directly in the email body. Once executed, the exploit collects passwords and two-factor authentication tokens. The token theft is particularly damaging: it lets the attacker retain access even after a password reset. The exploit also grabs the organization's email directory and up to 90 days of archived communications.
The pattern, and the Zimbra blind spot
It's the third major zero-click email vulnerability exploited by nation-state actors in roughly 18 months, following the ProxyNotShell campaign against Exchange and a separate Outlook vulnerability. Each campaign exploited a different mail platform, but the operational signature's the same: bypass the user's judgment entirely and execute on the server side. What distinguishes the Zimbra campaign is detection. Zimbra's government install base is smaller than Exchange's, which means fewer SOC teams are watching Zimbra logs, fewer threat-hunting queries are tuned for Zimbra telemetry, and dwell time is likely longer.
The Treasury Department's Financial Crimes Enforcement Network purchased a Zimbra standard support subscription in February 2025, according to federal contracting data. That purchase doesn't establish whether FinCEN ran the vulnerable version or was targeted. But Zimbra's presence inside a Treasury bureau, combined with Laundry Bear's stated interest in government financial departments, means the question of scope isn't settled.
CISA urged organizations to patch all Zimbra mail software immediately, monitor for suspicious activity using the technical indicators in the advisory, and follow full remediation guidance rather than relying on a patch alone. For practitioners, the Monday-morning checklist starts with inventory: do any of your agency's systems run Zimbra, including instances stood up outside standard procurement channels by individual bureaus or contractors? If the answer is yes, assume active adversary presence until a forensic review says otherwise. The advisory's indicators of compromise are publicly available. The patch isn't optional.
Published ·Deep Fathom