CybersecurityJuly 24, 2026· via Dark Reading

Russian hackers weaponize Zimbra zero-day with phishing lures

Russian hackers weaponize Zimbra zero-day with phishing lures

Image : Dark Reading

Russia-linked hackers are sending carefully crafted phishing emails that trick users into surrendering their Zimbra mailbox credentials through a now-patched zero-day vulnerability. The group, tracked as either Laundry Bear or Void Blizzard, combines social engineering with technical exploitation to harvest sensitive data from organizations in the US and Ukraine.

A two-step attack that lowers the bar for compromise

The phishing messages require only that a recipient open or preview the email; no link click is necessary. Once the message loads, the embedded exploit triggers the Zimbra flaw (CVE-2023-34192) and quietly delivers a credential-harvesting page to the victim’s browser. Security vendor Rapid7 reported that the attack chain is designed to steal mailbox contents without any additional user interaction, making it effective even against security-aware recipients.

CISA has issued guidance urging organizations to apply the supplied patch immediately and to review mail-server logs for signs of exploitation. The agency’s advisory highlights the risk of persistent access once the flaw is triggered, noting that compromised accounts can be leveraged for further espionage or data exfiltration.

Why it matters

This campaign underscores how quickly state-backed actors weaponize patched vulnerabilities when patches are not universally applied. Organizations running unpatched Zimbra servers face a clear and present danger of credential theft and mailbox compromise. The “half-click” approach lowers the technical barrier for entry, meaning even modestly resourced threat actors can achieve meaningful results. For defenders, the lesson is straightforward: prioritize patching and monitor for exploitation patterns before adversaries do.


Source: Dark Reading. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on Dark Reading →

← Back to home