>samit_hota
Back to security news
SN-2026-174CriticalOpen

Russian Hackers Exploit Zimbra Webmail Flaw to Steal Emails and 2FA Codes

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Zimbra Collaboration Suite, Zimbra Webmail
#news#vulnerability-disclosure#zimbra

Russian state-sponsored espionage actors have been leveraging a zero-click Zimbra webmail zero-day vulnerability to compromise Western email infrastructure, targeting government and critical sector mailboxes. Joint intelligence advisories highlight a sustained campaign designed to gain covert access to sensitive communications without requiring any victim interaction beyond the delivery of a malicious email message.

Exploit Mechanics and Data Exfiltration

The attack vectors center around Zimbra Collaboration Suite deployments, where attackers deliver malicious payloads embedded directly within incoming messages. Because the execution relies on a zero-click webmail rendering flaw, users do not need to click links, open attachments, or interact with the interface for the malicious script to trigger.

Once executed within the target user’s webmail session, the payload initiates automated routines to siphon sensitive data. The primary exfiltration targets include:

  • Complete mailbox records, specifically targeting the last 90 days of sent and received messages.
  • Global address lists and internal organizational directories.
  • Stored credentials saved in the web browser context.
  • Two-factor authentication (2FA) recovery codes and active authentication tokens.

By securing recovery codes alongside session tokens, the threat actors retain long-term persistent access even if basic authentication password resets occur.

Attribution to Laundry Bear

Security agencies have attributed this activity to Laundry Bear, a Kremlin-backed advanced persistent threat (APT) group known for strategic espionage operations against NATO member states, defense industrial base entities, and diplomatic missions. The group routinely hoards zero-day flaws in widely deployed webmail and messaging enterprise software to conduct long-term reconnaissance and intelligence gathering.

Specific Remediation Guidance

Administrators operating Zimbra Collaboration Suite instances should immediately apply the latest security updates provided by the vendor. Organizations running affected installations should perform the following response steps:

  • Terminate all active Zimbra webmail session tokens and force an enterprise-wide password reset.
  • Invalidate and re-issue all multi-factor authentication recovery keys and reset 2FA configurations for impacted users.
  • Inspect mail server logs for anomalous bulk message retrieval via Webmail APIs, EWS, or IMAP protocols, specifically searching for bulk extraction queries targeting 90-day email windows.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call