Skip to content
You can now search across every topic, entity and event.What's new
LAUNDRY BEAR
OrganisationRU

LAUNDRY BEAR

LAUNDRY BEAR is a Russian state-supported cyber actor, also tracked as Void Blizzard, CL-STA-1114, TA488 and UNK_PitStop.

Last refreshed: 24 July 2026 · Appears in 1 active topic

Key Question

LAUNDRY BEAR needs no click to steal your mail, so what happens once Zimbra finally patches?

Timeline for LAUNDRY BEAR

#11 23 Jul

Ran a zero-click exploit chain against Zimbra webmail

Cybersecurity: Threats and Defences: Zimbra preview leaks mail to Russia
View full timeline →

Background

Fifteen agencies, including CISA, the NSA, the FBI, Britain's NCSC, France's ANSSI and the Dutch AIVD, jointly named LAUNDRY BEAR as the Russian state-supported actor behind a zero-click exploit of Zimbra webmail on 23 July 2026. Viewing a single email hands the group a target's last 90 days of mail and their organisation's entire staff directory.

The group first drew a formal attribution in May 2025, when Dutch intelligence tied it to password-spraying and pass-the-cookie theft against cloud email under the tracking name Void Blizzard. It also appears in threat-intelligence reporting as CL-STA-1114, TA488 and UNK_PitStop. The zero-click chain marks a sharp jump in tradecraft from the credential-theft methods it used a year earlier.

Fifteen co-sealing agencies is an unusually broad Coalition for a single actor, more than double the two-to-four names a routine attribution once carried. The advisory itself predicts LAUNDRY BEAR will pivot to other webmail platforms as Zimbra patching improves, meaning today's fix addresses one door rather than the group's underlying capability.

Common Questions
Who is LAUNDRY BEAR?
LAUNDRY BEAR is a Russian state-supported cyber actor, also tracked as Void Blizzard, CL-STA-1114 and TA488, named by a 15-nation Coalition on 23 July 2026 for a zero-click exploit of Zimbra webmail.Source: CISA
What is Void Blizzard?
Void Blizzard is an earlier tracking name for LAUNDRY BEAR, used by Dutch intelligence when it first attributed the group's password-spraying and pass-the-cookie tradecraft in May 2025.Source: CISA
How does the LAUNDRY BEAR Zimbra attack work?
Merely previewing a single email in Zimbra Collaboration Suite triggers the exploit, handing LAUNDRY BEAR the target's last 90 days of mail and the organisation's Global Address List with no further user action.Source: CISA
Which agencies signed the LAUNDRY BEAR advisory?
Fifteen agencies co-sealed advisory AA26-204A on 23 July 2026, including CISA, the NSA and FBI in the US, Britain's NCSC, France's ANSSI and the Dutch AIVD.Source: CISA
Source Material