The NCSC and 15 international partner agencies have jointly attributed a zero-click email exfiltration campaign to a Russian state-supported group, LAUNDRY BEAR, which exploits vulnerable versions of Zimbra Collaboration Suite (ZCS) webmail. The technique, named 'beehive' or 'Ulej', compromises victims simply by having them view a malicious email, requiring no click or attachment execution, granting persistent access to email data. The campaign, active since July 2025, was reportedly tested against Ukrainian targets before being used against NATO-aligned Western organisations, and analysis suggests AI assistance in developing the exploit's codebase.
laundry-bear
1 post
UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations