Actor Profile

Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored cyberespionage group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police. The group's operational mandate centers on intelligence collection against organizations aligned with Russian strategic interests, with sustained focus on NATO member states and Ukraine. Since at least 2024, Laundry Bear has demonstrated persistent targeting of government, defense, and critical infrastructure entities, leveraging both technical exploitation and social engineering to achieve email account compromise and data exfiltration.

TTPs (Tactics, Techniques, Procedures)

Laundry Bear combines initial access via phishing (T1566) with exploitation of CVE-2025-66376, a cross-site scripting vulnerability in Zimbra Collaboration Suite's Classic UI that enables zero-click JavaScript execution when victims view malicious HTML emails. The group employs adversary-in-the-middle (AiTM) phishing kits (T1557) that impersonate Zimbra login portals to harvest credentials and session cookies (T1539). Post-compromise, attackers create unauthorized Zimbra application passcodes to maintain persistence (T1098) and bypass multi-factor authentication. Data collection (T1114.002) targets the victim's last 90 days of emails, credentials, Global Address Lists, and 2FA tokens. Exfiltration occurs via dual channels: DNS A-record queries for smaller encoded data (T1048.003) and HTTPS uploads of compressed mailbox archives to attacker-controlled infrastructure running the "Flowerbed" collection framework (T1041).

Targets & Patterns

Laundry Bear targets organizations across multiple sectors including the Defense Industrial Base (DIB), federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology. Geographic focus centers on NATO member states and Ukraine, reflecting Russian strategic intelligence priorities. The group has successfully compromised organizations supporting Ukraine, including defense, transportation, and aviation sector entities. Targeting patterns indicate collection requirements focused on government operations, law enforcement activities, and defense-related information. The selection of Zimbra Collaboration Suite as an attack vector suggests deliberate focus on organizations using this email platform, which is common in government and enterprise environments. The 2024 Dutch National Police compromise demonstrates willingness to target sensitive law enforcement infrastructure for personnel data collection.

Historical Context

Laundry Bear was first publicly attributed in May 2025 by Dutch intelligence agencies following investigation of a 2024 compromise of the Dutch National Police that exposed personnel information. Microsoft began tracking the same cluster as Void Blizzard, documenting activity dating to at least 2024. The current Zimbra exploitation campaign represents continuation of the group's email-focused intelligence collection operations. Earlier in 2025 (prior to this July advisory), BleepingComputer reported a separate Laundry Bear campaign targeting Ukraine's military using charity-themed phishing emails delivering malware disguised as donation requests. The group exploited CVE-2025-66376 as a zero-day before Zimbra patched it in November 2025, and CISA subsequently tagged the vulnerability as actively exploited. The sustained targeting of Ukraine-aligned entities and NATO members demonstrates consistent operational focus aligned with Russian intelligence priorities throughout 2024-2025.

Defensive Recommendations

  • Update Zimbra Collaboration Suite to the latest version to patch CVE-2025-66376 and review all systems for exposure to this XSS vulnerability in the Classic UI
  • Hunt for connections to known Laundry Bear infrastructure including domains mailnalysis.com, emailanalytics.com.ua, zimbrastat.com, zimbra-metadata.com, istc-cloud.com, and zmailanalytics.com
  • Monitor DNS logs for anomalous A-record query patterns indicative of DNS-based exfiltration (T1048.003) and investigate HTTPS uploads of compressed archives to external infrastructure
  • Audit Zimbra application passcodes for unauthorized entries, particularly those containing 'ZimbraWeb', and revoke any suspicious tokens to prevent MFA bypass persistence mechanisms (T1098)
  • Implement phishing-resistant multi-factor authentication and monitor authentication logs for AiTM indicators such as session cookie reuse, impossible travel patterns, and credential use from unexpected geolocations (T1557, T1539)

---

# Geopolitical Context

Geopolitical Context

The campaign attributed to Laundry Bear (also tracked as Void Blizzard) reflects sustained Russian intelligence collection priorities targeting NATO member states, Ukraine, and organizations aligned with Western strategic interests. First publicly attributed by Dutch intelligence agencies in May 2025 following a 2024 compromise of the Dutch National Police, the group appears focused on espionage operations consistent with Russian foreign policy objectives. The targeting of Defense Industrial Base entities, government agencies, and organizations supporting Ukraine suggests intelligence requirements related to Western military assistance, defense capabilities, and Ukrainian operational support. The exploitation of CVE-2025-66376 as a zero-day prior to its November 2025 patch demonstrates technical sophistication and operational persistence, with continued targeting of unpatched infrastructure indicating opportunistic collection against vulnerable organizations. The use of adversary-in-the-middle phishing kits alongside technical exploitation reflects a multi-vector approach designed to maximize access and persistence across diverse target environments.

State Actor Alignment

Laundry Bear is attributed by Dutch intelligence agencies and CISA to Russian state sponsorship. The group's targeting patterns—focused on NATO members, Ukraine, and entities supporting Ukrainian defense efforts—align with Russian strategic intelligence priorities. Microsoft's tracking of the same cluster as Void Blizzard corroborates the attribution. The compromise of Dutch National Police personnel data in 2024 and documented intrusions into organizations supporting Ukraine's defense, transportation, and aviation sectors are consistent with collection requirements that would serve Russian military and foreign policy decision-making. The group's operational focus since at least 2024 on intelligence gathering against Western and Ukrainian targets suggests tasking aligned with Russia's ongoing conflict in Ukraine and broader strategic competition with NATO.

Business Impacty pro region

The campaign has direct implications for European security, particularly NATO member states and Ukraine. The documented compromise of Dutch National Police systems and targeting of government, law enforcement, and defense sectors across NATO countries represents a significant counterintelligence challenge for European institutions. Organizations supporting Ukraine—including defense, transportation, and aviation entities—face elevated risk, as stolen communications may inform Russian military operations or diplomatic strategy. The breadth of targeted sectors (DIB, government, education, energy, media, NGOs, technology) suggests wide-aperture collection designed to map institutional relationships and policy deliberations. For European organizations using Zimbra Collaboration Suite, the campaign underscores vulnerability to state-sponsored exploitation of enterprise communication platforms. The theft of Global Address Lists and 90 days of email data enables network mapping and follow-on targeting, potentially compromising sensitive policy discussions, defense procurement details, and coordination mechanisms for Ukraine assistance.

Forecast

If organizations fail to patch CVE-2025-66376 and implement phishing-resistant authentication, Laundry Bear is likely to continue exploiting vulnerable Zimbra infrastructure for intelligence collection. Given the group's demonstrated persistence and the strategic value of email data from government, defense, and Ukraine-aligned entities, sustained targeting of NATO member states and Ukrainian support networks is probable through at least 2026. If the conflict in Ukraine remains active, intelligence requirements driving this collection are likely to persist, with potential expansion to target diplomatic communications related to conflict resolution or sanctions policy. Organizations that deploy robust email security controls and phishing-resistant MFA may reduce successful compromises, though the group's use of multiple vectors (zero-day exploitation, AiTM phishing) suggests adaptive tradecraft. If additional Zimbra vulnerabilities are identified, rapid exploitation by Laundry Bear and similar Russian APT groups should be anticipated given demonstrated capability and targeting priorities.