{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/email-theft/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":["LAUNDRY BEAR"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Zimbra Collaboration Suite (ZCS)"],"_cs_severities":["critical"],"_cs_tags":["phishing","zero-click","espionage","state-sponsored","zimbra","email-theft"],"_cs_type":"threat","_cs_vendors":["Zimbra"],"content_html":"\u003cp\u003eGCHQ’s National Cyber Security Centre (NCSC) and international partners have exposed LAUNDRY BEAR, a Russian state-supported advanced persistent threat (APT) group, for an ongoing zero-click phishing campaign. Active since July 2025, this campaign leverages a previously unknown exploit, internally dubbed \u0026quot;beehive\u0026quot; (or \u0026quot;Ulej\u0026quot;), targeting vulnerable versions of Zimbra Collaboration Suite (ZCS) webmail services. Unlike traditional phishing, the \u0026quot;beehive\u0026quot; exploit allows the attackers to gain extensive and sustained access to sensitive email information and compromised networks without any user interaction beyond viewing a malicious email. The campaign, which was initially trialed on Ukrainian victims, has subsequently targeted numerous Western organizations across sectors including defence, government, education, energy, law enforcement, media, NGOs, and technology, indicating an espionage objective to covertly acquire email data. The use of Artificial Intelligence in developing the codebase for this operation has also been noted.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe LAUNDRY BEAR threat group, with Russian state support, sends a specially crafted malicious email to a target organization using a vulnerable Zimbra Collaboration Suite (ZCS) instance.\u003c/li\u003e\n\u003cli\u003eA user within the target organization views the malicious email in their ZCS webmail client.\u003c/li\u003e\n\u003cli\u003eUpon viewing, the \u0026quot;beehive\u0026quot; zero-click exploit is automatically triggered within the vulnerable ZCS software, requiring no further user interaction (e.g., clicking a link or opening an attachment).\u003c/li\u003e\n\u003cli\u003eThe exploit grants the attackers extensive and sustained access to the target user's email account.\u003c/li\u003e\n\u003cli\u003eAttackers proceed to steal sensitive email information from the compromised account.\u003c/li\u003e\n\u003cli\u003eThe threat actors establish persistent access to the compromised email system or broader network, facilitating long-term espionage activities.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe LAUNDRY BEAR campaign has resulted in the successful theft of sensitive email information and persistent access to compromised networks for espionage purposes. Since July 2025, organizations utilizing Zimbra Collaboration Suite (ZCS) have been targeted, with specific victim sectors in the US including defence, government, education, energy, law enforcement, media, NGOs, and technology. The techniques were first observed being tested on Ukrainian victims before being deployed against NATO member countries. A successful attack can lead to the exfiltration of confidential communications, intellectual property, and other critical data, posing significant national security and economic risks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately patch all Zimbra Collaboration Suite (ZCS) installations to the latest secure version to remediate the \u0026quot;beehive\u0026quot; zero-click vulnerability.\u003c/li\u003e\n\u003cli\u003eEnhance network monitoring capabilities for anomalous activity originating from or destined for Zimbra Collaboration Suite (ZCS) components.\u003c/li\u003e\n\u003cli\u003eOrganizations should refer to the advisories from NCSC (\u003ca href=\"https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign\"\u003ehttps://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign\u003c/a\u003e) and NSA (\u003ca href=\"https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF\"\u003ehttps://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF\u003c/a\u003e) for comprehensive mitigation advice.\u003c/li\u003e\n\u003cli\u003eStrengthen online account security practices, including multi-factor authentication, across all enterprise applications.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T14:41:39Z","date_published":"2026-07-23T14:41:39Z","id":"https://feed.craftedsignal.io/briefs/2026-07-russian-laundry-bear-zimbra-zero-click/","summary":"The Russian state-supported threat group LAUNDRY BEAR is exploiting a zero-click vulnerability, dubbed 'beehive,' in the Zimbra Collaboration Suite (ZCS) webmail service, actively stealing sensitive emails and gaining persistent access to compromised networks since July 2025 by merely viewing a malicious email, with Western organizations across various sectors being targeted.","title":"Russian State-Backed 'LAUNDRY BEAR' Exploits Zimbra Zero-Click Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-russian-laundry-bear-zimbra-zero-click/"}],"language":"en","title":"CraftedSignal Threat Feed - Email-Theft","version":"https://jsonfeed.org/version/1.1"}