Russian Hackers Exploit Zimbra Webmail Flaw to Steal Emails and 2FA Codes
- CVE ID
- N/A
- Affected Products / Orgs
- Zimbra Collaboration Suite, Zimbra Webmail
Russian state-sponsored espionage actors have been leveraging a zero-click Zimbra webmail zero-day vulnerability to compromise Western email infrastructure, targeting government and critical sector mailboxes. Joint intelligence advisories highlight a sustained campaign designed to gain covert access to sensitive communications without requiring any victim interaction beyond the delivery of a malicious email message.
Exploit Mechanics and Data Exfiltration
The attack vectors center around Zimbra Collaboration Suite deployments, where attackers deliver malicious payloads embedded directly within incoming messages. Because the execution relies on a zero-click webmail rendering flaw, users do not need to click links, open attachments, or interact with the interface for the malicious script to trigger.
Once executed within the target user’s webmail session, the payload initiates automated routines to siphon sensitive data. The primary exfiltration targets include:
- Complete mailbox records, specifically targeting the last 90 days of sent and received messages.
- Global address lists and internal organizational directories.
- Stored credentials saved in the web browser context.
- Two-factor authentication (2FA) recovery codes and active authentication tokens.
By securing recovery codes alongside session tokens, the threat actors retain long-term persistent access even if basic authentication password resets occur.
Attribution to Laundry Bear
Security agencies have attributed this activity to Laundry Bear, a Kremlin-backed advanced persistent threat (APT) group known for strategic espionage operations against NATO member states, defense industrial base entities, and diplomatic missions. The group routinely hoards zero-day flaws in widely deployed webmail and messaging enterprise software to conduct long-term reconnaissance and intelligence gathering.
Specific Remediation Guidance
Administrators operating Zimbra Collaboration Suite instances should immediately apply the latest security updates provided by the vendor. Organizations running affected installations should perform the following response steps:
- Terminate all active Zimbra webmail session tokens and force an enterprise-wide password reset.
- Invalidate and re-issue all multi-factor authentication recovery keys and reset 2FA configurations for impacted users.
- Inspect mail server logs for anomalous bulk message retrieval via Webmail APIs, EWS, or IMAP protocols, specifically searching for bulk extraction queries targeting 90-day email windows.
Related content
Zimbra Collaboration Suite Patches Stored XSS Vulnerability
Security NewsCISA Adds Two New Actively Exploited Vulnerabilities to KEV Catalog
Security NewsCritical Authentication Bypass in Oracle E-Business Suite Added to CISA KEV
Security NewsCritical Unauthenticated RCE (CVE-2026-46817) in Oracle EBS Payments Actively Exploited
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call