A Russia-linked hacking group has spent the past year targeting nuclear scientists, defense contractors, and government employees in a cyberespionage campaign exploiting a previously unknown flaw in Zimbra webmail software, according to a joint advisory from US and allied intelligence agencies released Thursday, per CNN.
The group, tracked by Dutch intelligence as Laundry Bear and also known as Void Blizzard, exploited the vulnerability, tracked as CVE-2025-66376, as a zero-day for at least five months before Zimbra patched it in November 2025. The exploit requires no social engineering: a vulnerable Zimbra webmail client mishandles specially crafted HTML in an email and automatically runs attacker-controlled JavaScript the moment the message is opened or previewed, without the victim clicking any link. The malware then exfiltrates roughly 90 days of the victim’s email history, the organization’s full address directory, and two-factor authentication tokens to a command-and-control server, according to The Record.
According to the advisory, Laundry Bear conducted extensive targeting of Ukrainian government and military entities before turning its focus to the United States and other NATO members, testing techniques in the Ukrainian theater ahead of wider deployment. Targets included federal and local governments, law enforcement, and the defense, education, and energy sectors.
Proofpoint, the email security firm that investigated part of the campaign, said the hackers specifically targeted entities and users with an interest in nuclear fusion. Researcher Greg Lesnewich said this was likely intended to gauge how far Western researchers had advanced in the field. Sherrod DeGrippo of Palo Alto Networks said the attackers likely sought strategically valuable information on Western military logistics and policy decisions.
The Department of Energy did not respond to a request for comment on Proofpoint’s findings, and the FBI, the National Security Agency, and the Russian Embassy in Washington did not immediately respond to requests for comment.


