Security agencies from over 15 countries have issued a joint warning regarding a massive espionage wave by Russian hacker groups.
The group known as Laundry Bear, also referred to as Void Blizzard, CL-STA-1114 or UAC-0190, is specifically exploiting vulnerabilities in the widely used email software Zimbra. This warning, coordinated by the USA, UK, Australia, Canada, New Zealand, and several European nations, dates back to July 23, 2026.
Dangerous Zero-Click Exploits
Particularly insidious are the attackers’ methods, which do not require any interaction from victims. A single zero-click exploit is enough—just opening or previewing an email is sufficient to activate the malware. Security researchers from Unit 42 and the US agency CISA have thoroughly analyzed this attack vector.
Essentially, the exploit injects JavaScript code that intercepts sensitive data. The list of targeted information is extensive: complete email archives from the last 90 days, browsing histories, global address books, and login credentials. Alarmingly, session tokens, CSRF tokens, and backup codes for two-factor authentication are also stolen, giving attackers permanent access to compromised accounts.
Moreover, the cybersecurity industry has observed that this hacker group utilizes artificial intelligence to develop their exploit codes. Unit 42 has identified nine specific command-and-control servers (C2) and domains linked to this operation.
From Ukraine to the World
The espionage campaign has reportedly been active since at least July 2025. Initially, the attacks were directed at targets within Ukraine. In March 2026, security professionals noted a significant increase in attack attempts against Ukrainian government agencies and critical infrastructure.
Since then, the scope of targets has greatly expanded, now affecting NATO member states, countries of the Commonwealth of Independent States (CIS), and nations in Africa. The impacted sectors resemble a “who’s who” of critical infrastructure:
- Defense and governmental agencies
- Energy and transportation infrastructure
- Financial and technology companies
- Educational and research institutions
- Media organizations and non-governmental organizations
Arrests and Legal Proceedings
The campaign is linked to a Russian company named Yutek-NN. Authorities have identified Denis Obrezko, a former employee of the Russian Federal Security Service (FSB) and deputy director at Yutek-NN. Obrezko was arrested in Thailand and is currently awaiting trial in Boston.
The exploited security vulnerability CVE-2025-66376 was initially disclosed in January 2026. However, the first patches were available as early as November 2025 for Zimbra versions 10.0.18 and 10.1.13. It wasn’t until July 22, 2026, that Zimbra released another security update for version 10.1.20, which addresses a total of nine vulnerabilities, including cross-site scripting issues in the classic web client.
Urgent Need for Action
Security authorities are urging all organizations that still use vulnerable Zimbra versions to install the latest patches immediately. Experts also recommend implementing passkeys and monitoring account logs for unusual activity over the past 90 days.
The question is not whether further attacks will follow, but how many organizations will take this warning seriously before the next incident is reported.

