Multiple cybersecurity and government advisories report that the Russian state-sponsored hacking group Laundry Bear (also tracked as Void Blizzard, TA488, and CL-STA-1114) is targeting organizations that run Zimbra Collaboration Suite (ZCS) webmail servers. The activity is described as ongoing for at least a year, with reporting that the campaign has been running since July 2025.
The reported intrusion path combines social engineering with exploitation of a Zimbra vulnerability. Outlets say Laundry Bear sends phishing emails that function as “half-click” or “zero-click” style lures, where a victim may only need to open or preview a message. In parallel, the group exploits an unpatched Zimbra flaw to gain access and steal email content. The vulnerability is described as now patched, with CISA urging organizations to apply updates.
A joint advisory cited across sources attributes the campaign to Laundry Bear and frames it as targeting both government and commercial environments. The advisory is supported by multiple international agencies, including the NSA, FBI, CISA, and counterparts from the Netherlands, the UK, Australia, Canada, and other countries.