Russian "Laundry Bear" threat actor rinses Western victims with zero-click exploit
Intelligence agencies get lathered up about a Moscow-linked espionage group also tracked as Void Blizzard.
A Russian threat actor armed with a new zero-click exploit is stealing sensitive emails from Western organisations and attempting to establish persistent access to compromised networks.
That's the warning from the US National Security Agency (NSA), the UK’s National Cyber Security Centre (NCSC) - part of GCHQ - and intelligence agencies from 14 other countries.
Following the long, eccentric security sector tradition of giving advanced threat groups and cyberwar actors ridiculous names (see Haywire Kitten, Kryptonite Panda and Spandex Tempest), Dutch authorities christened the Moscow-linked group Laundry Bear. Microsoft tracks it under the slightly more sensible moniker of Void Blizzard.
The state-backed espionage group has been active since at least April 2024, according to the NSA.
Laundry Bear initially stole emails at scale by purchasing compromised credentials and directing targets to convincing fake login pages. It used a modified version of the open-source Evilginx toolkit to capture victims’ passwords and session tokens, bypass authentication and access Microsoft Exchange accounts.
Then in July 2025, the group adopted a more sophisticated capability called Ulej - Russian for “Beehive” - to compromise organisations using Zimbra Collaboration Suite. It targeted emails, passwords, address books, two-factor authentication tokens and application passcodes.
Beehive enables the threat actors to gain "extensive and sustained access" to emails without requiring them to click a link or open a file. All they need to do is view a malicious email within a vulnerable version of the ZCS webmail service to be compromised.
A security spin cycle
The absence of financial extortion and the campaign’s covert, persistent nature suggest that Laundry Bear is focused on state-backed espionage. Its techniques were extensively deployed against Ukrainian targets before being turned on organisations in the US and other NATO countries, indicating that Ukraine served as both a priority target and a testing ground.
“This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organisations,” said Beth Hopkins, chief operating officer of the NCSC.
READ MORE: Five Eyes orders "whole of society" response to AI security crisis set to erupt in "months"
“With our international partners, we strongly encourage organisations to familiarise themselves with the zero-click techniques described in the advisory, which could be used against other platforms, and act on the mitigation advice.
“We will continue to call out malicious cyber activity supported by the Russian state and urge everyone to follow NCSC guidance to raise resilience, including steps to strengthen online account security.”
Laundry Bear is known to have rinsed (sorry) targets across the defence, government, education, energy, law-enforcement, media, technology and non-profit sectors.
The buzz around Beehive
Security agencies warned that Beehive could be adapted to exploit other vulnerabilities. As organisations patch their Zimbra installations, Laundry Bear is expected to turn its attention to other email platforms used across the West.
The warning comes as the government seeks to improve Britain’s cyber resilience. Earlier this month, businesses from across the economy signed a public Cyber Resilience Pledge to strengthen their defences against evolving threats.
Dan Jarvis, the UK security minister, said: “We’re working hand in hand with our allies to expose Russian state-supported hackers targeting Western organisations. It’s particularly concerning that these thugs tested their methods on victims in Ukraine before targeting members of NATO.
“Organisations across the UK should sign up to the NCSC’s Early Warning service to ensure they can quickly secure their systems against similar activity.”
READ MORE: Chinese IoT ‘kill switches’ could disable Britain’s critical systems and infrastructure, MPs warn
READ MORE: Hollowgraph malware turns Microsoft 365 calendars into secret-stealing "dead drop"
Commenting on the intelligence agencies' advisory, Dray Agha, senior manager of security operations at Huntress, said, "These exploits are a worst-case scenario for defenders because it is a zero-click attack, meaning simply viewing the email in a vulnerable client triggers the compromise.
"This completely bypasses traditional employee security training and gives state-backed hackers a silent, invisible backdoor into sensitive communications without the victim ever making a mistake. Fortunately, this is why defence-in-depth is advised, as where the human security layer is porous, the technical defensive layer can step in.
"Organisations shouldn't just rely on their staff acting as a 'human firewall'. Rapid software patching, coupled with layered technical defences, is the only reliable safety net against modern state-sponsored threats."