Technology

Russian APT Laundry Bear perfects zero-click phishing assault


An rising risk actor linked with confidence to the Russian state is concentrating on Western organisations with a novel zero-click phishing assault approach designed to compromise electronic mail platforms and acquire persistent entry to its goal networks.

Flagged by the UK’s Nationwide Cyber Safety Centre (NCSC), alongside its 5 Eyes companions and sister companies from throughout Europe, the brand new operation has been given the identify Laundry Bear, and has efficiently stolen delicate knowledge from a number of targets in sectors akin to defence, schooling, vitality, authorities, legislation enforcement, media and non-governmental organisations (NGOs).

The superior persistent risk (APT) group has seemingly been round since 2024, and has developed a zero-click exploit termed beehive or Ulej that particularly targets Zimbra Collaboration Suite (ZCS) software program. The NCSC mentioned this method was initially examined in opposition to Ukrainian targets previous to being turned in opposition to Western organisations, which is “indicative of espionage” and means Laundry Bear is “nearly actually” appearing with Moscow’s assist.

“This phishing marketing campaign demonstrates how hostile actors will ruthlessly adapt strategies and exploit weak know-how in pursuit of their goals to steal delicate info from Western organisations,” mentioned NCSC chief working officer Beth Hopkins.

“With our worldwide companions, we strongly encourage organisations to familiarise themselves with the zero-click strategies described within the advisory which could possibly be used in opposition to different platforms, and act on the mitigation recommendation. 

“We are going to proceed to name out malicious cyber exercise supported by the Russian state and urge everybody to comply with NCSC steerage to lift resilience, together with steps to strengthen on-line account safety.” 

Busy bees

The background to Laundry Bear’s marketing campaign dates again to Might 2025 when the Dutch authorities warned of a cluster of malicious exercise concentrating on Microsoft Alternate and abusing reputable utility programming interfaces (APIs) to exfiltrate bulk knowledge. At this stage ,the group seemed to be utilizing a malicious web site masquerading as a European Defence and Safety Summit registration portal.

Nonetheless, from round July 2025, Laundry Bear shifted to a much more technical phishing methodology with its custom-developed beehive approach – technical evaluation carried out by the NCSC means that synthetic intelligence (AI) instruments had been used within the era of a easy codebase for this objective.

Not like the Microsoft marketing campaign, beehive allows Laundry Bear to realize sustained entry to its goal’s emails with no enter from the consumer. Extra often, a sufferer should click on a hyperlink or open a file to allow this sort of entry however on this occasion, they solely must view a malicious electronic mail inside a weak model of ZCS’ webmail service with the intention to be compromised.

Beehive particularly targets a flaw tracked as CVE-2025-66376, a saved cross-site-scripting (XSS) vulnerability in ZCS’ traditional consumer interface that permits attackers to abuse cascading fashion sheets (CSS) @import directives in electronic mail HTML.

Zimbra patched this flaw in November 2025 and the NCSC is urging any customers that haven’t up to date to right away patch it and conduct pressing community monitoring.

The NCSC warned that whereas CVE-2025-66376 particularly exists in ZCS, the beehive approach itself could possibly be readily tailored to use different vulnerabilities. It added that as extra organisations replace their ZCS situations, Laundry Bear would very seemingly look to focus on different electronic mail programs because the pool of potential victims empties out.

Huntress senior supervisor of safety operations Dray Agha mentioned: “These exploits are a worst-case state of affairs for defenders as a result of it’s a zero-click assault, that means merely viewing the e-mail in a weak shopper triggers the compromise. This utterly bypasses conventional worker safety coaching and provides state-backed hackers a silent, invisible backdoor into delicate communications with out the sufferer ever making a mistake.

“This is the reason defence-in-depth is suggested, as the place the human safety layer is porous, the technical defensive layer can step in. Organisations shouldn’t simply longer depend on their employees appearing as a human firewall. Fast software program patching, coupled with layered technical defences, is the one dependable security internet in opposition to trendy state-sponsored threats.”