Cybersecurity Policy Report, Cyber Defense Agencies Warn About Russian Cyber Espionage Group, (Jul 24, 2026)
Organizations Mentioned:Federal Bureau of Investigation
A cyber espionage group working for the Russian government has been exploiting vulnerabilities in e-mail systems to target defense agencies, governments, law enforcement, media, and nongovernmental organizations, according to an advisory published yesterday by the U.S. and 15 allied nations.
Known as Laundry Bear, the hacking group has operated for at least a year, exploiting a vulnerability in Zimbra Collaboration Suite (ZCS) software for which a patch has been available since last November, the advisory says.
“LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data,” it says.
“Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited,” the advisory notes.
“Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications,” it explains.
Organizations should “regularly update their mail service software and continuously monitor their email systems and emails for malicious activity,” the advisory recommends.
“Russian state-sponsored cyber actors have spent years quietly extracting configuration data from poorly configured routers across critical infrastructure,” Brett Leatherman, head of the Cyber Division at the Federal Bureau of Investigation, said in a news release. “This advisory gives network defenders the visibility to spot this activity and the mitigations to counter it. The FBI will work with our partners to continue to expose this tradecraft and hold these actors accountable.”
In addition to the FBI, the advisory was co-signed by the Cybersecurity and Infrastructure Security Agency, National Security Agency, and departments of Defense and Treasury. The signatories also include cyber defense agencies from Australia, Canada, the Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, the Netherlands, New Zealand, Poland, Spain, Sweden, and the United Kingdom.
News: FederalLegislation InternationalLegislation DataSecurity