Decoding the world of cybersecurity

Russian zero-click campaign targets Zimbra mail

The NCSC and international partners say Russian state-supported actors used a Zimbra zero-click exploit to steal email data from Western organisations.

Russian zero-click campaign targets Zimbra mail
Summary
  • The NCSC and partners attribute the campaign to Russian state-supported actors tracked as LAUNDRY BEAR.
  • The technique, known as beehive or Ulej, can compromise vulnerable Zimbra webmail when a malicious email is viewed.
  • The advisory warns that similar techniques could be adapted to other email platforms.

The National Cyber Security Centre and international partners have exposed a Russian state-supported campaign using a zero-click technique to compromise organisations running Zimbra Collaboration Suite.

The UK agency said the campaign, attributed to a threat group it calls LAUNDRY BEAR, used an exploit known as “beehive” or “Ulej” to steal email data. Unlike ordinary phishing, the technique does not require a user to click a link or open an attachment. A user only has to view a malicious email within a vulnerable version of Zimbra webmail for compromise to occur.

The campaign has been active since July 2025 and has targeted organisations using Zimbra Collaboration Suite. The NCSC said US organisations were targeted across defence, government, education, energy, law enforcement, media, non-governmental organisations, and technology. The joint advisory characterises the activity as espionage and almost certainly carried out with Russian state support.

The public warning urges organisations using Zimbra to apply mitigation advice, patch immediately, and improve network monitoring. The NCSC also warned that beehive could be adapted to exploit other vulnerabilities, and that the group is very likely to target other email systems as more organisations update Zimbra.

Security Minister Dan Jarvis MBE said: “Today’s action shows we’re working hand-in-hand with our allies to expose Russian state-supported hackers targeting Western organisations. It’s particularly concerning that these thugs tested their methods on victims in Ukraine, before targeting members of NATO.”

Email remains a prime target for espionage because it contains the working record of organisations: policy discussions, legal advice, procurement details, meeting schedules, operational planning, credentials, attachments, and relationship maps. Persistent access to mailboxes can support intelligence collection, impersonation, lateral movement, and further compromise across trusted networks.

The zero-click element reduces the value of user awareness as the main defence. Training can help with ordinary phishing, but a compromise triggered by viewing a message depends more heavily on patching, server hardening, exposure management, platform monitoring, and rapid detection. Organisations running self-hosted collaboration systems need accurate inventories, ownership of patch windows, and visibility into abnormal server and mailbox activity.

Zimbra has a particular profile in parts of government, education, hosting, and smaller enterprise environments. Collaboration platforms can remain in service for long periods because migration is disruptive, expensive, or politically difficult. That makes lifecycle maintenance and administrative ownership central to risk.

The advisory’s warning about adaptation to other platforms widens the exposure. Email security cannot be handled as a single-product issue. Organisations need detection for unexpected mailbox access, suspicious forwarding rules, abnormal authentication, unusual server processes, and data exfiltration patterns. Patch management also needs to be tied to business-critical services rather than left as a general IT backlog.

The campaign shows how hostile-state actors can use a specialist vulnerability in a familiar communications platform to reach strategic information. Where email systems hold the record of sensitive decisions and relationships, mail server resilience becomes part of national-security and governance risk.

×