Russian hackers exploit Zimbra and Exchange webmail flaws
A Russian state-backed hacking group tracked as Laundry Bear, also called Void Blizzard or TA488, has been breaking into government, defense, and now also telecom, finance, hospitality, and aerospace email accounts since at least July 2025 by exploiting flaws in Zimbra webmail and Microsoft Exchange Outlook Web Access. Victims only had to open or preview a rigged email for the attackers to read months of mail, steal saved passwords, and grab two-factor login codes. US, Dutch, and other Western agencies issued a joint warning on the Zimbra flaw, and the group has since shifted to a new Exchange bug, deploying a backdoor called OWAReaper that keeps working even after passwords are reset or the server is rebuilt.
- Started
- Jul 1, 2025
- Latest activity
- Jul 30, 2026
- Attributed to
- Laundry Bear (Void Blizzard, also tracked as TA488)Confirmed
- Where
- United States, Netherlands, Ukraine
- Sectors
- Government, Defence
- Scale
- multiple Western government, defense, telecommunications, financial services, hospitality, and aerospace organizations, mainly in the US
Current status
No credible reporting with new facts dated after August 20, 2026 was found; a September 1, 2026 WebProNews piece on the OWAReaper backdoor was located but its title and available snippets match the same July 29-30, 2026 Proofpoint/CSOonline/Infosecurity Magazine reporting already in the timeline, with no new victims, patch status, or attribution details.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
Government attribution for the earlier Zimbra campaign stands; the Exchange OWA pivot to the same actor cluster is based on research firm reporting (Proofpoint), not a new government statement.
Impact
Attackers read up to 90 days of email, the full company address book, browser-saved passwords, and two-factor recovery codes, then used stolen mailbox access to run further phishing. The newer OWAReaper backdoor grants itself owner-level mailbox permissions that survive password resets and even a full reinstall of the server, and it can receive instructions or send stolen data through GitHub commits, parsed emails, direct connections, or hidden DNS traffic, making it hard to fully evict.
What to do
IT teams running Zimbra should confirm they are on patched version 10.1.13 or 10.0.18. Exchange OWA admins should confirm they have applied Microsoft's June 9, 2026 permanent patch for CVE-2026-42897, since the flaw was under active exploitation as a zero-day for weeks before that fix shipped. Patching alone does not remove an existing infection: OWAReaper's mailbox-permission changes can survive both a password reset and a full server reimage, so mailbox permissions and delegate access should be audited directly on any server that was ever unpatched.
Timeline
-
Aug 20, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Aug 7, 2026
Consumer-security press recapped the CISA-led advisory, reporting that Laundry Bear has compromised more than 10 Western organizations by exploiting the Zimbra flaw since July 2025; the report did not add new details on the Exchange OWA pivot or OWAReaper.
Activetech.yahoo.com -
Jul 30, 2026
Analysts detailed that the OWAReaper backdoor sets owner-level mailbox permissions that persist through password resets and full server reinstalls, and that it communicates with attackers through GitHub commits, parsed emails, direct connections, and DNS tunneling.
Activetechtimes.com -
Jul 30, 2026
Further coverage reported that Microsoft rated the underlying Exchange OWA flaw at maximum severity and that reported victims now include telecommunications, financial services, hospitality, and aerospace organizations in the US and Europe, beyond the government and defense targets first named.
Activearstechnica.com -
Jul 29, 2026
Researchers reported the same actor cluster pivoting to a new Exchange Outlook Web Access exploit, deploying a persistent backdoor called OWAReaper.
Activebleepingcomputer.com -
Jul 26, 2026
Follow-up reporting confirmed the Zimbra flaw, tracked as CVE-2025-66376, had been patched, while the extent of the espionage campaign continued to be assessed.
Containedyahoo.com -
Jul 23, 2026
Researchers and CISA disclosed that Void Blizzard, also known as Laundry Bear, had been exploiting a Zimbra zero-day to read email at Western government and defense organizations.
Activethehackernews.com -
Jul 23, 2026
CISA, NSA, FBI, and Dutch intelligence agencies publicly attributed the Zimbra zero-click phishing campaign to Russian state-backed actors and released a patched-version advisory.
Activecisa.gov -
Jul 1, 2025
Laundry Bear (Void Blizzard) begins exploiting a Zimbra Collaboration Suite flaw against Western government and commercial mail servers.
Activecisa.gov
Sources
- Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite CISA Jul 23, 2026
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox access BleepingComputer Jul 29, 2026
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes TheHackerNews Jul 23, 2026
- Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets DarkReading Jul 23, 2026 unverified
- Laundry Bear pivots to new exploit days after Zimbra alert Computer Weekly Jul 29, 2026
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes Proofpoint Jul 23, 2026
- Outlook Web Access backdoor spreads via half-click trick GBHackers Jul 23, 2026
- Zimbra email servers hacked by Russian group BleepingComputer Jul 23, 2026
- Russian attackers break into Zimbra email servers SC World Jul 23, 2026
- Max-severity Exchange server flaw under active exploitation by Kremlin hackers Ars Technica Jul 30, 2026
- Russian Hackers Breached Exchange Servers With OWAReaper: Implant Survives Re-Imaging Tech Times Jul 30, 2026
- OWAReaper Backdoor Targets Microsoft Exchange Users Windows Report Jul 30, 2026
- Russian hackers can steal emails without a click Yahoo Tech / Fox News (CyberGuy) Aug 7, 2026
Related reports
- Zimbra bug can let attackers steal email without clicks Jul 23, 2026
- Zimbra bug can expose secrets Jul 23, 2026
- Laundry Bear phishing attacks target Zimbra users Jul 23, 2026
- Russian attackers stole emails from US allies Jul 23, 2026
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes Jul 23, 2026
- Zimbra flaw can expose email and account data Jul 23, 2026
- Microsoft Exchange emails can expose mailboxes Jul 23, 2026
- Outlook Web Access flaw delivers OWAReaper backdoor Jul 23, 2026