HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Zero‑Click “Beehive” Exploit in Zimbra Webmail Enables Russian APT Group “Laundry Bear” to Steal Emails from Western Organizations

Russian state‑supported actors behind the Laundry Bear APT group have leveraged a zero‑click “beehive” exploit against vulnerable Zimbra Collaboration Suite webmail servers, stealing email content from organisations in defence, government, education, energy, law‑enforcement, media, NGOs and technology. The attack bypasses user interaction, underscoring the need for continuous monitoring, rapid patching and security‑awareness controls to stay audit‑ready.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 ncsc.gov.uk
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
7 sector(s)
Actions
4 recommended
📰
Source
ncsc.gov.uk

Zero‑Click “Beehive” Exploit in Zimbra Webmail Enables Russian APT Group “Laundry Bear” to Steal Emails from Western Organizations

What Happened — Russian state‑supported actors operating the “Laundry Bear” APT group have been using a zero‑click exploit, dubbed “beehive” (or “Ulej”), against vulnerable versions of the Zimbra Collaboration Suite (ZCS) webmail service. By merely viewing a malicious email, the exploit grants the attackers persistent access and allows them to exfiltrate sensitive email data without any user interaction. The campaign, active since July 2025, has already resulted in the theft of email content from organisations across defence, government, education, energy, law‑enforcement, media, NGOs and technology sectors.

Why It Matters for Compliance & Audit Readiness

  • Zero‑click attacks bypass traditional user‑focused controls, highlighting the need for continuous monitoring of endpoint and network telemetry as evidence of effective SOC 2 Security and Availability controls.
  • Demonstrates the importance of maintaining up‑to‑date vulnerability‑management processes (Patch Management, Configuration Management) and documenting remediation as audit‑ready evidence.
  • Reinforces the requirement for robust Security Awareness Training that covers advanced phishing techniques, even those that do not require user clicks, to satisfy SOC 2 Common Criteria for Risk Management.

Who Is Affected — Primarily organisations that deploy Zimbra Collaboration Suite, spanning government, defence, education, energy, law‑enforcement, media, NGOs and technology firms.

Recommended Actions

  • Verify ZCS version and apply the latest security patches immediately.
  • Enable and tune network‑level anomaly detection to flag unusual mailbox‑access patterns.
  • Incorporate the “zero‑click” scenario into Security Awareness Training and update phishing‑simulation playbooks.
  • Document patch‑management and monitoring activities as part of your SOC 2 evidence repository.

Source: NCSC advisory

Technical Notes

  • Attack vector: zero‑click exploit of a web‑mail vulnerability in ZCS (no CVE disclosed publicly yet).
  • Data exfiltrated: full email contents, including attachments and metadata.
  • The group is believed to be state‑supported and may adapt the technique to other email platforms.

Source: NCSC advisory

📰 Original Source
https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →