
A Russian state-supported threat group has been using a zero-click technique against vulnerable Zimbra Collaboration Suite installations to steal sensitive email data without requiring users to click a link or open an attachment.
On 23 July 2026, the UK’s National Cyber Security Centre and cyber agencies from 15 other countries publicly exposed the campaign. The group, tracked as LAUNDRY BEAR and also known as Void Blizzard, has targeted Western organisations using Zimbra since at least July 2025. The NCSC assesses that the activity is almost certainly conducted with Russian state support. Read the joint warning on the NCSC website.
What actually happened
The campaign uses a technique called Beehive, or Ulej, exploiting CVE-2025-66376, a stored cross-site scripting vulnerability in the Classic user interface of Zimbra Collaboration Suite.
The malicious code can execute when a specially crafted email is simply viewed in a vulnerable webmail session. Technical investigations found that attacks could harvest credentials, session information, backup two-factor authentication codes, browser-saved passwords and up to approximately 90 days of mailbox content.
Zimbra fixed CVE-2025-66376 in releases 10.0.18 and 10.1.13 on 6 November 2025. Zimbra 10.0 has since reached end of life, so organisations should run a currently supported and fully updated release rather than relying solely on the original minimum patched version.
| Detail | What is known |
|---|---|
| Threat group | LAUNDRY BEAR, also tracked as Void Blizzard |
| Target software | Zimbra Collaboration Suite, particularly the Classic UI |
| Vulnerability | CVE-2025-66376, a stored XSS flaw |
| Trigger | Viewing a crafted email in a vulnerable Zimbra webmail session |
| Potentially stolen data | Emails, credentials, address information, session data and 2FA recovery codes |
| Original fix | Zimbra 10.0.18 and 10.1.13, released 6 November 2025 |
| Current action | Update to a supported secure release and investigate potentially exposed systems |
Why zero-click attacks matter
Traditional phishing usually requires someone to click, download, log in or approve a request. Staff awareness therefore remains an important defence against ordinary phishing.
Beehive changes that calculation. The NCSC says the victim only needs to view a malicious email in a vulnerable Zimbra webmail service. It also warns that the technique could potentially be adapted to exploit vulnerabilities in other email platforms.
That makes technical controls particularly important. Regular vulnerability management can identify missing security updates, while network penetration testing can help reveal weaknesses in internet-facing infrastructure.
What UK businesses should do
If you operate Zimbra, identify the installed version and update unsupported or vulnerable systems immediately. Organisations that may have been exposed should also investigate rather than assuming that applying a patch removes access already gained.
Monitor unusual authentication, mailbox changes, newly created application passwords and suspicious network activity. Managed SOC services can support ongoing detection and investigation.
Businesses should also maintain appropriate email security services and use dark web monitoring to help identify compromised credentials. Patching should be treated as routine operational work rather than an occasional project. It is one of the IT management tasks that quietly get neglected.
The latest Cyber Security Breaches Survey 2025/2026 found that only 33% of businesses monitored user activity and 34% had a policy to apply software security updates within 14 days. Three per cent of businesses experienced cyber-facilitated fraud during the previous 12 months. Among businesses reporting a financial cost from such fraud, the median perceived cost was £500.
Frequently asked questions
What is zero-click phishing?
It is an attack in which exploitation does not require the victim to click a malicious link or open an attachment. In the Beehive campaign, viewing a crafted email in vulnerable Zimbra webmail could trigger the exploit.
Does multi-factor authentication stop Beehive?
Not by itself. Observed attacks targeted session information and backup 2FA codes, so MFA should be combined with patching, session management and monitoring.
Who is affected by CVE-2025-66376?
The vulnerability is specific to affected Zimbra Collaboration Suite installations. Microsoft 365 and Google Workspace are not vulnerable to this particular CVE, although similar zero-click techniques could potentially target other software vulnerabilities.
Is security awareness training still useful?
Yes. Most phishing attacks still depend on human interaction. The lesson from Beehive is that awareness training must sit alongside rapid patching, vulnerability management and continuous monitoring.
If you want a clearer picture of exposed systems, patching priorities and monitoring gaps, Northern Star’s managed IT support in London can help you review your current environment.












