HomeRisk ManagementsRussian Hackers Take Advantage of New Zero-Click Attack

Russian Hackers Take Advantage of New Zero-Click Attack

Published on

spot_img

In a significant escalation of cyber threats, it has been reported that Russian state-supported hackers are adopting a novel attack technique known as a Zero-Click exploit. This innovative method bypasses traditional phishing strategies by not requiring any user interaction with malicious emails, allowing hackers to infiltrate networks more silently and effectively. A recent joint advisory issued by cybersecurity agencies in the West has raised alarms regarding this alarming development in cyber espionage.

The advisory, published on July 23, reveals that these state-backed cyber actors have been specifically targeting various Western government and commercial organizations, particularly utilizing the Zimbra Collaboration Suite (ZCS) software. This targeting has reportedly been ongoing since at least July 2025. Among the sectors most vulnerable to these espionage attacks are critical areas such as defense, government, education, law enforcement, media, non-governmental organizations (NGOs), energy, and technology.

The joint warning was crafted by prominent cybersecurity entities, including the UK National Cyber Security Centre (NCSC), the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI). It also includes contributions from intelligence agencies of the “Five Eyes” alliance, which consists of Canada, Australia, New Zealand, and several European agencies.

It is noteworthy that this campaign has been linked to a well-documented cyber espionage operation known as Laundry Bear. This group is also referred to as Void Blizzard and UAC-0190 in various intelligence circles. The Laundry Bear campaign exploits a zero-day vulnerability in ZCS, specifically identified as CVE-2025-66376. This vulnerability, disclosed to the public in November 2025, facilitates a zero-click exploit termed “beehive,” which effectively allows hackers to siphon off emails and other sensitive materials without requiring any action from the victim.

In stark contrast to conventional phishing techniques, which often rely on a user clicking a malicious link or opening a harmful attachment, the Laundry Bear campaign uniquely circumvents these steps. Instead, it leverages a view-based exploit, which activates merely by the target opening a malicious email in a vulnerable version of the webmail service. This intelligent evasion technique poses a significant risk to organizations that may not have robust safeguards.

Upon successfully executing the exploit, the attackers aim to exfiltrate emails from the past 90 days and gather further sensitive information. Furthermore, the Laundry Bear group employs methods to sustain persistent access to the compromised networks by secretly pilfering passwords and bypassing multi-factor authentication measures through the use of session tokens.

In light of these significant threats, organizations using ZCS are urged to act swiftly to patch these critical vulnerabilities and enhance their network monitoring capabilities. Beth Hopkins, the Chief Operating Officer of the NCSC, emphasized the urgent need for organizations to familiarize themselves with these zero-click techniques and take action as per the mitigation advice provided in the advisory. “This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations,” she stated.

To further mitigate risk, system administrators are advised to remain vigilant for any suspicious activity within their networks. The advisory also recommends that organizations consider integrating third-party authentication services that support passkeys, particularly for accessing ZCS and other services that lack native passkey support. This addition can significantly reduce the likelihood of hackers exploiting stolen credentials to gain entry into servers.

In a noteworthy detail, the advisory indicates that technical analysis of the campaign has found evidence of artificial intelligence being used in the creation of a simplified codebase for the operation. This revelation aligns with earlier warnings from intelligence agencies regarding the potential for malicious actors to leverage AI in their cyber campaigns.

As the landscape of cyber threats evolves, the adoption of zero-click attacks underscores the pressing need for organizations to bolster their defenses against sophisticated tactics employed by state-sponsored threat actors. The collaborative efforts of international cybersecurity agencies aim to provide much-needed guidance to mitigate these risks, emphasizing the importance of proactive strategies in safeguarding sensitive information.

Source link

Latest articles

Coding Agents: The New Frontier of Enterprise Security

Idan Plotnik: AI Development Tools Have Become Enterprises' Newest Attack Surface In the ever-evolving landscape...

Ghost in the Calendar: The Microsoft 365 Calendar Implant

On July 20, 2026, a team of security researchers from Group-IB unveiled a troubling...

Cryptohack Roundup – BitMex Shuts Down

Recent Crypto Developments: Significant Legal Actions and Financial Losses In the rapidly evolving realm of...

New Kimi K3 AI Agent Identifies Redis Remote Code Execution Vulnerabilities in Only 27 Minutes

Kimi K3 AI Unveils New Frontiers in Cybersecurity with Redis Vulnerability Discovery In a remarkable...

More like this

Coding Agents: The New Frontier of Enterprise Security

Idan Plotnik: AI Development Tools Have Become Enterprises' Newest Attack Surface In the ever-evolving landscape...

Ghost in the Calendar: The Microsoft 365 Calendar Implant

On July 20, 2026, a team of security researchers from Group-IB unveiled a troubling...

Cryptohack Roundup – BitMex Shuts Down

Recent Crypto Developments: Significant Legal Actions and Financial Losses In the rapidly evolving realm of...