The Russian state-backed APT group is tracked as LAUNDRY BEAR, a name initially coined by the Netherlands AIVD and MIVD . The threat activity has been ongoing since at least July 2025 . The group's targeting is assessed as espionage for the Russian Federation, with "extensive Ukrainian targeting, prior to use against U.S. and other NATO allies" — Ukraine was used as a "testbench for malicious cyber techniques before broader global deployment" . Compromised sectors include defense, education, energy, law enforcement, media, finance, transportation, and technology .
CVE-2025-66376 is a stored cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite (ZCS) Classic UI, caused by abuse of CSS @import directives in HTML email messages . It affects ZCS 10.0.x before 10.0.18 and 10.1.x before 10.1.13 . The vulnerability was patched by Zimbra in November 2025 . The CVSS score is reported as 7.2 (High) by some sources or 6.1 (Medium) by others . CISA added it to its Known Exploited Vulnerabilities Catalog in March 2026 .
This is a zero-click / view-based exploit: no user interaction beyond opening (viewing) a malicious email is required — no clicking links or opening attachments . Once triggered, a custom JavaScript payload is delivered to the victim's browser via the stored XSS .
The exploit targets :
The group's custom data exfiltration and aggregation capability is called "beehive" . Officials warned the group could likely adapt and reuse this capability to exploit other vulnerabilities . The advisory details a multi-stage exfiltration architecture using both HTTPS and DNS tunneling (via a tool called "Ulej" with a "Flowerbed" server component), with DNS queries structured per RFC 1035 and base32-encoded payloads .
The advisory urges organizations to :
The vulnerability was exploited as a zero-day for about five months (July–November 2025) before patches were released, and the group continues to actively exploit unpatched instances . The advisory assesses the activity as "almost certainly" Russian state-backed espionage — no financial extortion motive was ever observed .