Russian-linked hackers are taking aim at inboxes in a way that feels almost unfair. A message can sit there looking ordinary, yet the simple act of opening or previewing it can give attackers a path to passwords, 2FA tokens, and a pile of private email. That is the alarm CISA is sounding around a group tracked as Laundry Bear, especially for organizations running vulnerable Zimbra systems.
The big twist here is that the old advice about “don’t click suspicious links” is no longer enough on its own. CISA says the campaign can trigger when a malicious email is merely displayed, which means the danger can begin before anyone hits a button or opens an attachment. The target is the Classic interface in certain versions of Zimbra Collaboration Suite, where hidden JavaScript can run automatically.
That matters because Zimbra is used by governments, schools, businesses, and other groups that depend on email for daily work. The flaw, identified as CVE-2025-66376, was patched in November 2025, but not every organization moved fast enough. Attackers love that gap between the fix being available and the fix actually being installed.
According to the warning, Laundry Bear can pull more than just a password. The malicious code may grab authentication data, email addresses, and as much as 90 days of mailbox content, which can include internal conversations, contract chatter, invoices, and password reset notices. That kind of haul gives attackers a rich view into how an organization operates and who matters inside it.
The group does not stop at stealing information, either. CISA says the attack can create a new Zimbra application passcode, which may allow the hackers to keep coming back even after the main password changes. That is the part that makes this campaign especially nasty, because a password reset can create a false sense of safety while a separate back door stays open.
Laundry Bear has also been tied to other delivery methods, including fake login pages that mimic real email portals. Those pages can catch usernames, passwords, and session cookies, which means even accounts protected by conventional multifactor authentication are not automatically safe. It is a reminder that attackers will use whatever looks convincing, especially when the goal is long-term access rather than a quick smash-and-grab.
The infrastructure behind the campaign is designed to hide in the noise. CISA says stolen data can move out through DNS requests and encrypted HTTPS traffic, which makes the activity easier to blend into normal network chatter. On top of that, the group has used domains that look like legitimate Zimbra-related services, making the whole setup feel even more believable to the people being targeted.
What gives the campaign extra weight is the target list. Investigators and intelligence agencies have tied Laundry Bear to organizations connected to defense, government, education, energy, law enforcement, media, nonprofits, and technology. The pattern points to cyberespionage, not random chaos, with a focus on gathering information that can be useful later.
That is why patching has to happen quickly and completely. One updated server is not enough if another system is still exposed, and one password change is not enough if a hidden application passcode remains active. Security teams need to check for suspicious logins, odd mailbox behavior, unfamiliar passcodes, and traffic going to known malicious domains or servers.
For everyday users, the best move is to stay skeptical when an email suddenly asks for attention, especially if it sparks a fresh login prompt or looks slightly off. It also helps to use unique passwords, prefer phishing-resistant authentication where possible, and report strange account activity fast instead of waiting to see if it happens again. When an inbox can become a doorway without much warning, the smallest red flag deserves a hard look.
