Zero‑Click Phishing Campaign Exploits Zimbra Webmail (CVE‑2025‑66376) Targeting Government and Financial Entities
What Happened — Russian‑aligned APT group Laundry Bear leveraged a zero‑click exploit (CVE‑2025‑66376) in Zimbra Collaboration Suite’s webmail to deliver a malicious JavaScript payload that runs as soon as an email is opened. The campaign has hit U.S., U.K., European, Australian, New Zealand, Ukrainian and NATO‑linked organizations, exfiltrating recent emails, passwords, contact lists and two‑factor tokens.
Why It Matters for Compliance & Audit Readiness
- Demonstrates how a patched vulnerability can be weaponised in a “zero‑click” scenario, bypassing traditional user‑training controls.
- Highlights the need for SOC 2‑aligned access‑control policies, continuous monitoring of privileged account activity, and evidence that patch management is enforced and auditable.
- Provides a real‑world example to validate that your organization can produce defensible audit evidence of credential‑access restrictions and incident‑response readiness.
Who Is Affected – Government agencies, defense contractors, transportation firms, financial services, and maritime organizations that run Zimbra Collaboration Suite.
Recommended Actions
- Verify that all Zimbra deployments are running the November 2025 patch (or later) for CVE‑2025‑66376.
- Enable multi‑factor authentication (MFA) on all webmail accounts and enforce strict session‑monitoring controls.
- Incorporate the exploit into your SOC 2 access‑control testing regime and capture evidence of remediation for audit purposes.
Technical Notes – The attack uses a zero‑click, cross‑site‑script payload embedded in email bodies; no user interaction is required. Data exfiltrated includes the last 90 days of email, credentials, contact lists, and MFA tokens. Source: The Record