Dormant Critical impact Espionage Checked 1w ago

Russian hackers exploit Zimbra and Exchange webmail flaws

A Russian state-backed hacking group tracked as Laundry Bear, also called Void Blizzard or TA488, has been breaking into government, defense, and now also telecom, finance, hospitality, and aerospace email accounts since at least July 2025 by exploiting flaws in Zimbra webmail and Microsoft Exchange Outlook Web Access. Victims only had to open or preview a rigged email for the attackers to read months of mail, steal saved passwords, and grab two-factor login codes. US, Dutch, and other Western agencies issued a joint warning on the Zimbra flaw, and the group has since shifted to a new Exchange bug, deploying a backdoor called OWAReaper that keeps working even after passwords are reset or the server is rebuilt.

Started
Jul 1, 2025
Latest activity
Jul 30, 2026
Attributed to
Laundry Bear (Void Blizzard, also tracked as TA488)Confirmed
Where
United States, Netherlands, Ukraine
Sectors
Government, Defence
Scale
multiple Western government, defense, telecommunications, financial services, hospitality, and aerospace organizations, mainly in the US

Current status

No credible reporting with new facts dated after August 20, 2026 was found; a September 1, 2026 WebProNews piece on the OWAReaper backdoor was located but its title and available snippets match the same July 29-30, 2026 Proofpoint/CSOonline/Infosecurity Magazine reporting already in the timeline, with no new victims, patch status, or attribution details.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

Government attribution for the earlier Zimbra campaign stands; the Exchange OWA pivot to the same actor cluster is based on research firm reporting (Proofpoint), not a new government statement.

Impact

Attackers read up to 90 days of email, the full company address book, browser-saved passwords, and two-factor recovery codes, then used stolen mailbox access to run further phishing. The newer OWAReaper backdoor grants itself owner-level mailbox permissions that survive password resets and even a full reinstall of the server, and it can receive instructions or send stolen data through GitHub commits, parsed emails, direct connections, or hidden DNS traffic, making it hard to fully evict.

What to do

IT teams running Zimbra should confirm they are on patched version 10.1.13 or 10.0.18. Exchange OWA admins should confirm they have applied Microsoft's June 9, 2026 permanent patch for CVE-2026-42897, since the flaw was under active exploitation as a zero-day for weeks before that fix shipped. Patching alone does not remove an existing infection: OWAReaper's mailbox-permission changes can survive both a password reset and a full server reimage, so mailbox permissions and delegate access should be audited directly on any server that was ever unpatched.

Timeline

  1. Aug 20, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Aug 7, 2026

    Consumer-security press recapped the CISA-led advisory, reporting that Laundry Bear has compromised more than 10 Western organizations by exploiting the Zimbra flaw since July 2025; the report did not add new details on the Exchange OWA pivot or OWAReaper.

    Activetech.yahoo.com
  3. Jul 30, 2026

    Analysts detailed that the OWAReaper backdoor sets owner-level mailbox permissions that persist through password resets and full server reinstalls, and that it communicates with attackers through GitHub commits, parsed emails, direct connections, and DNS tunneling.

    Activetechtimes.com
  4. Jul 30, 2026

    Further coverage reported that Microsoft rated the underlying Exchange OWA flaw at maximum severity and that reported victims now include telecommunications, financial services, hospitality, and aerospace organizations in the US and Europe, beyond the government and defense targets first named.

    Activearstechnica.com
  5. Jul 29, 2026

    Researchers reported the same actor cluster pivoting to a new Exchange Outlook Web Access exploit, deploying a persistent backdoor called OWAReaper.

    Activebleepingcomputer.com
  6. Jul 26, 2026

    Follow-up reporting confirmed the Zimbra flaw, tracked as CVE-2025-66376, had been patched, while the extent of the espionage campaign continued to be assessed.

    Containedyahoo.com
  7. Jul 23, 2026

    Researchers and CISA disclosed that Void Blizzard, also known as Laundry Bear, had been exploiting a Zimbra zero-day to read email at Western government and defense organizations.

    Activethehackernews.com
  8. Jul 23, 2026

    CISA, NSA, FBI, and Dutch intelligence agencies publicly attributed the Zimbra zero-click phishing campaign to Russian state-backed actors and released a patched-version advisory.

    Activecisa.gov
  9. Jul 1, 2025

    Laundry Bear (Void Blizzard) begins exploiting a Zimbra Collaboration Suite flaw against Western government and commercial mail servers.

    Activecisa.gov

Sources

Related reports