Logo
Home
language
Политика конфиденциальности·Условия обслуживания

Russian Hackers Can Steal Emails Without You Clicking

Russian Hackers Can Steal Emails Without You Clicking

Russian Hackers Can Steal Emails Without You Clicking
Opening a strange email can seem safe if you don't click links or open attachments. However, a Russian hacking group has found a way around this safety tip.
The US Cybersecurity and Infrastructure Security Agency says the Russian group, called Laundry Bear, can access certain email accounts just by opening a bad email. This attack targets organizations using unpatched Zimbra Collaboration Suite.
When you open the email, hidden code can collect passwords and messages. You might not even notice anything is wrong.
The US Cybersecurity Agency, along with other security groups, warned about this threat. They say the group has successfully targeted over 10 Western organizations since July 2025.
Investigators think Iranian hackers might be behind a cyberattack on Minnesota water systems.
Russian state-sponsored hackers can steal passwords and up to 90 days of email when users view bad messages in unpatched Zimbra accounts.
You can watch the replay of our free CyberGuy Live class, 'Sick of Spam?' and get our spam-stopping checklist.
Our free class, 'Sick of Spam?' is over, but you can still watch and download the checklist. Kurt 'CyberGuy' Knutsson shows you how to reduce robocalls, spam texts, and junk email.
Get the free replay and checklist now at CyberGuyLive.com.
Laundry Bear exploits a security flaw known as CVE-2025-66376. This affects the Classic user interface in certain Zimbra Collaboration Suite versions.
Zimbra is an email platform used by governments, schools, and businesses as an alternative to Microsoft Exchange or Google Workspace. Attackers can put bad code inside a specially crafted HTML email.
The person reading the email doesn't need to open an attachment. The attack also doesn't ask for a password on a phishing page. However, the email needs to appear on the screen.
Laundry Bear used this flaw before Zimbra released a patch in November 2025. CISA later added the vulnerability to its list of flaws that hackers actively exploit.
The available patch closes the security hole. Yet Laundry Bear continues to target organizations that haven't installed the update.
The campaign has reached organizations connected to defense and government. Attackers have also targeted education, energy, law enforcement, media, and technology companies.
The malicious code tries to collect the target's last 90 days of email. This could include private conversations or information about meetings.
Laundry Bear also collects the person's email address and password. The attack can copy the organization's Global Address List.
CISA says the exploit also targets two-factor authentication tokens. A stolen token or session cookie can let an attacker enter an account without logging in again.
Fake password-manager alerts could put your vault at risk.
Malicious code inside an email can run when a vulnerable Zimbra webmail client displays the message, giving hackers access to sensitive data.
Stealing information provides immediate value, but Laundry Bear also tries to preserve its access. The attack creates a new Zimbra application passcode.
An unauthorized passcode can give hackers another way into the mailbox. This access may continue even after someone changes the main account password.
Organizations should treat an unknown passcode as a sign that someone may have entered the account.
Laundry Bear sends the stolen information to servers controlled by the group. CISA says the attackers use a collection framework called Flowerbed.
Attackers can hide encoded information inside DNS requests. Laundry Bear sends larger collections through encrypted HTTPS connections.
Laundry Bear also uses adversary-in-the-middle phishing kits. These tools create login pages that closely resemble legitimate email portals.
CISA's indicators of compromise include domains that impersonated Zimbra infrastructure. Organizations should review CISA's complete list.
Proofpoint found that Laundry Bear sent messages from attacker-controlled Proton Mail accounts and compromised email addresses.
Dutch intelligence agencies publicly identified Laundry Bear in May 2025. Their investigation linked the group to a 2024 breach of the Dutch National Police.
Since at least 2024, Laundry Bear has focused on organizations connected to Russian strategic interests.
Microsoft has documented compromises involving defense organizations and entities in transportation and aviation.
These campaigns suggest the group cares more about long-term intelligence collection than a quick financial payout.
CISA warns that Laundry Bear can compromise vulnerable Zimbra accounts without requiring users to click a link or open an attachment.
The strongest protection starts with the organization running the email server. However, you can still take steps to spot suspicious activity.
Administrators should update Zimbra Collaboration Suite to a currently supported version and install all available security fixes.
Installing the patch blocks the known flaw, but it cannot undo a previous intrusion. Security teams should review CISA's published indicators of compromise.
Review every Zimbra application passcode connected to an account. Revoke any passcode that the account owner or IT department cannot verify.
Administrators should examine mailbox access records and forwarding settings. They should also look for unfamiliar filters or sent emails.
Contact your IT or security team if you notice unfamiliar sent messages or unexpected password resets.
Wait until your IT department has patched the server and removed unauthorized access. Then change your email password and any other password you reused.
CISA recommends phishing-resistant multifactor authentication where organizations can support it.
Strong antivirus software can help detect malicious downloads and follow-up malware connected to a broader phishing campaign.
An email login page can look convincing and still belong to an attacker. Instead of following a link, open your organization's known webmail address directly.
For years, we have warned you to avoid suspicious links and unexpected attachments. That advice still helps, but Laundry Bear shows why your organization also needs to keep the software behind your inbox updated.
Would you trust your workplace inbox if opening one message could expose 90 days of email without you clicking a link?
Sign up for my free CyberGuy Report.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP.
Copyright 2026 CyberGuy.com. All rights reserved.
Kurt 'CyberGuy' Knutsson is an award-winning tech journalist who has a deep love of technology, gear, and gadgets.