Context
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign.
Key points to note and next actions
- Russian state-supported actors have developed a new technique to target Western email platforms and gain persistent access to compromised networks. They have targeted Western organisations with a malicious campaign which uses a zero-click exploit coined “beehive” (or “Ulej”) to steal emails, the UK has warned.
- The NCSC, alongside cyber security agencies in 15 countries, has exposed activities of LAUNDRY BEAR, an advanced persistent threat group who specialise in the covert acquisition of email data. Since July 2025, LAUNDRY BEAR has successfully targeted and stolen sensitive email information from organisations using Zimbra Collaboration Suite (ZCS) software.
- In a joint advisory, the NCSC and partners warn LAUNDRY BEAR’s ongoing campaign is indicative of espionage and almost certainly carried out with Russian state support. Unlike traditional phishing campaigns, “beehive” allows the threat actors to gain extensive and sustained access to emails without a user’s input. Instead of clicking a link or opening a file, the user only has to view a malicious email within a vulnerable version of the ZCS webmail service to be compromised.
- Organisations that use ZCS are urged to follow the mitigation advice, including to immediately patch vulnerabilities and improve network monitoring capabilities.
