Laundry Bear (also known as Void Blizzard), a Russian state-sponsored hacking group, is exploiting an Outlook Web Access zero-day vulnerability in Microsoft Exchange to deliver the OWAReaper backdoor. The campaign targets organizations in Europe and the US for long-term mailbox persistence.
Russian state-sponsored group 'Laundry Bear' exploited CVE-2025-66376, a zero-click Zimbra vulnerability, to steal emails, passwords, 2FA codes, and directories from US and NATO targets for at least five months. The campaign used phishing emails requiring only message preview to trigger the exploit.
CISA warns that Russian state-sponsored group Laundry Bear (Void Blizzard) is actively exploiting a zero-click vulnerability in Zimbra Collaboration email servers to target Western government and commercial organizations. The exploit is combined with phishing attacks to steal email data.