← Blog · · df00tech

CISA Warns of Void Blizzard Exploiting Zimbra Zero-Click Flaw in Email Theft Campaign

security-news campaign

What Happened

CISA has issued a warning that the Russian state-sponsored hacking group tracked as Laundry Bear (also known as Void Blizzard) is targeting organizations that run Zimbra Collaboration email servers. According to the report, the group is combining phishing attacks with exploitation of a now-patched Zimbra vulnerability to gain access to victim mailboxes and steal email content.

Why It Matters

Organizations running Zimbra Collaboration servers for email are potentially at risk, particularly if patching has lagged. Email systems are high-value targets for state-sponsored actors because they provide direct access to sensitive correspondence, credentials, and further phishing pivot points into an organization. Attribution to a persistent, well-resourced state-sponsored group means affected organizations should assume a degree of operational sophistication and follow-up targeting.

What Defenders Should Do

  • Confirm Zimbra Collaboration servers are patched to the latest available version; prioritize patching if any instances remain outdated.
  • Review Zimbra server and mail access logs for anomalous authentication events, unusual mailbox access patterns, or unexpected API/webmail requests.
  • Hunt for phishing emails targeting privileged or high-value users, since the campaign reportedly combines phishing with the exploit.
  • Monitor for signs of mail exfiltration, such as bulk mailbox exports, unusual forwarding rule creation, or IMAP/EWS access from unfamiliar IP ranges.
  • Ensure MFA is enforced on webmail and admin interfaces where supported, and review Zimbra admin account activity.

Developing Story

Details on this campaign are still emerging, and full technical specifics of the exploited vulnerability and scope of victims have not been fully disclosed. This is net-new intelligence and should be treated as developing. For the original report, see BleepingComputer's coverage.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.