US agencies including CISA, NSA, and FBI have issued a warning about the Russian-linked APT group Laundry Bear, which is exploiting a patched vulnerability (CVE-2025-66376) in Zimbra servers to steal email accounts from unpatched systems. This zero-click exploit allows remote execution of malicious JavaScript through viewed emails, bypassing traditional phishing techniques. Laundry Bear's attacks utilize previous compromised accounts for credibility, embedding an encrypted payload in emails.
The malware extracts sensitive information, enables IMAP access, and exfiltrates data through secure channels. CISA recommends updating Zimbra, monitoring for anomalies, and employing multi-factor authentication to protect against these unauthorized accesses.