Russian state-sponsored hackers tracked as Laundry Bear are exploiting a zero-day vulnerability in Zimbra to target organizations in the US and Ukraine. The group deploys "half-click" phishing emails that trigger malicious code when victims merely open or preview the message, eliminating the need for users to click traditional links.
The attack vector is particularly dangerous because it bypasses standard email security controls designed to catch link-based phishing. Users who simply read an email in their preview pane become infected without taking any deliberate action. This dramatically lowers the activation barrier for successful compromise.
Zimbra, a widely deployed open-source email and collaboration platform, hosts the unpatched vulnerability that enables this attack. Government agencies and critical infrastructure operators running Zimbra installations face immediate risk. Ukrainian entities represent priority targets given current geopolitical tensions, though US organizations are also in scope.
Laundry Bear, a Russian-aligned group with operational history targeting governments and defense contractors, employs this method to establish initial access. Once inside compromised mail servers, operators gain the ability to harvest credentials, access sensitive communications, and deploy secondary payloads for lateral movement across networks.
Organizations running Zimbra should treat this as a critical threat. Interim defenses include disabling email preview functionality in client configurations, implementing additional email gateway inspection rules, and monitoring for suspicious Zimbra server behavior. Patches from Zimbra are expected but have not yet been released.
The half-click mechanism represents an evolution in phishing tradecraft. By removing user interaction requirements entirely, threat actors increase campaign success rates substantially. Security teams should prioritize communication to end users about the risks of preview panes and enable manual preview settings where technically feasible.
This exploitation pattern follows established Russian state actor behavior in targeting communications infrastructure. Organizations should assume breach and initiate forensic reviews of Zimbra logs for signs of unauthorized access
