Skip to content
Illustration by iStock; Security Management

No Click Necessary. Russian State-Sponsored LAUNDRY BEAR Gains Access to Email Accounts By Getting Victims to View Them

Russian state-sponsored threat actors have been using a malicious technique to compromise emails whenever the recipient views them, according to a joint advisory from 16 national cybersecurity agencies published this week.

The intelligence and threat intelligence communities have been tracking the technique for some time. But Thursday’s announcement was the first time that it was directly linked to Russian state-supported actors, commonly known as LAUNDRY BEAR or Void Blizzard.

The actors are using a technique called “Улей” or “Ulej”—beehive in Russian. It’s a zero-click exploit first used to target Ukrainian government entities before spreading to other NATO-aligned targets, the UK National Cyber Security Centre (NCSC) warned.

“Unlike traditional phishing campaigns, ‘beehive’ allows the threat actors to gain extensive and sustained access to emails without requiring a user’s input,” the NCSC said. “Instead of clicking a link or opening a file, the user only has to view a malicious email within a vulnerable version of the Zimbra Collaboration Suite webmail service to be compromised.”

The exploit attempts to exfiltrate the targeted organization’s email directory and the victim’s last 90 days of email communications, password, global address list, two-factor authentication tokens, and newly-created application passcodes to servers controlled by the threat actors.

“The phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations,” said Beth Hopkins, UK National Cyber Security Centre chief operating officer, in a statement.

Belarussian and Russian threat actors have been targeting webmail appliances with cross-site scripting (XSS) vulnerabilities for the past three years, according to analysis from cybersecurity firm Proofpoint.

“This type of XSS activity against webmail platforms is a half-click exploit, where opening the email is enough to allow the exploit to trigger, with no other social engineering required,” Proofpoint explained.

Groups that have used this technique include TA422 (also known as Sofacy, Forest Blizzard, Fancy Bear, and APT28), TA473 (WinterVivern), and TA445 (Ghostwriter or UNC 1151). In September 2025, Proofpoint said it identified a new threat actor—TA488—using an exploit of Zimbra Collaboration Suite (ZCS) email servers to target Ukrainian entities, U.S. nuclear installations, and the defense industrial base. The intelligence community has now linked TA488 to the group known as LAUNDRY BEAR, an advanced persistent threat actor.

How the Attack Works

LAUNDRY BEAR has been active since at least 2024. But in July 2025, it began to up its game. It started using a custom-developed capability—beehive—to target and exfiltrate sensitive user information from organizations using the Zimbra Collaboration Suite (ZCS) product (a collaborative software suite that includes an email server and Web client).

“The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing,” according to the advisory. “Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.”

To get access to its targets, LAUNDRY BEAR sends an email that contains a malicious JavaScript payload. It exploits CVE-2025-66376 so the JavaScript payload immediately executes once the victim opens and views the malicious email in the ZCS webmail platform.

LAUNDRY BEAR includes additional payloads and instructions within the HTML body of the email message to leverage CVE-2025-66376. These measures allow it to create new payloads that bypass basic threat detection signatures. The payloads also allow LAUNDRY BEAR to attempt to collect and exfiltrate information in 12 stages, including the victim’s saved passwords, two-factor authentication tokens, and more.

LAUNDRY BEAR has used email accounts, likely compromised through this exploit, to then send additional malicious emails to other targets—obfuscating its origins and frustrating anti-phishing tools and training.

Seqrite, a cybersecurity firm, first wrote about the attack method in March 2026 after studying a 22 January 2026 phishing email sent to the Ukrainian Hydrology government agency from a student of the National Academy of International Affairs.

“The email message written in Ukrainian, presents as a routine internship inquiry, where the student introduces as a fourth-year student asking if the recipient knows of any internship opportunities or contacts if they could reach out to,” according to the Seqrite blog. “Additionally, the sender apologizes in case the email reaches the wrong inbox, which is a classic tactic to build trust.”

How to Mitigate the Attack

The advisory recommended all organizations that use the ZCS webmail service “immediately prioritize” disuse of a vulnerable version. There is a patch available to address CVE-2025-66376 for ZCS versions 10.1.13 and 10.0.18.

“If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version,” the advisory explained.

Additionally, system administrators are urged to monitor any Internet-connected ZCS or other email systems and workstations that access those systems and apply available software updates. The advisory also recommended organizations consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys.

The advisory further suggested organizations implement network monitoring capabilities that allow collection and short-term retention of packet capture or NetFlow data, as well as maintaining log collections and storage. Taking these steps will allow organizations to monitor for and identify suspicious network activity, including large amounts of outbound data sent to Internet Protocols associated with virtual private server providers that the organization doesn’t use, frequent domain name server queries for a suspicious domain with random subdomains, a spike in connections to a server associated with a new domain, and connections to internal services leveraged by LAUNDRY BEAR for nefarious activity.

The advisory acknowledged that by the time an organization has identified a compromise related to this campaign, it’s likely that LAUNDRY BEAR has already obtained numerous sensitive and proprietary emails.

If an organization identifies activity associated with this LAUNDRY BEAR campaign, the advisory recommended that all organizational users have their application passcodes and two-factor authentication scratch keys revoked.

“Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements and creating unique credentials, specifically noting that compromised employees might have had any password stored in a password manager exfiltrated,” the advisory said.

The U.S. Cybersecurity and Infrastructure Agency (CISA), which joined the advisory, also cautioned that, as more organizations update their ZCS software, LAUNDRY BEAR might discontinue its campaign leveraging beehive while continuing to target email systems used by organizations in Western countries.

“The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts,” CISA wrote. “The authoring agencies recommend organizations regularly update their mail service software and continously monitor their email systems and emails for malicious activity.”

arrow_upward