
LAUNDRY BEAR
LAUNDRY BEAR is a Russian state-supported cyber actor, also tracked as Void Blizzard, CL-STA-1114, TA488 and UNK_PitStop.
Last refreshed: 24 July 2026 · Appears in 1 active topic
LAUNDRY BEAR needs no click to steal your mail, so what happens once Zimbra finally patches?
Timeline for LAUNDRY BEAR
Ran a zero-click exploit chain against Zimbra webmail
Cybersecurity: Threats and Defences: Zimbra preview leaks mail to RussiaBackground
Fifteen agencies, including CISA, the NSA, the FBI, Britain's NCSC, France's ANSSI and the Dutch AIVD, jointly named LAUNDRY BEAR as the Russian state-supported actor behind a zero-click exploit of Zimbra webmail on 23 July 2026. Viewing a single email hands the group a target's last 90 days of mail and their organisation's entire staff directory.
The group first drew a formal attribution in May 2025, when Dutch intelligence tied it to password-spraying and pass-the-cookie theft against cloud email under the tracking name Void Blizzard. It also appears in threat-intelligence reporting as CL-STA-1114, TA488 and UNK_PitStop. The zero-click chain marks a sharp jump in tradecraft from the credential-theft methods it used a year earlier.
Fifteen co-sealing agencies is an unusually broad Coalition for a single actor, more than double the two-to-four names a routine attribution once carried. The advisory itself predicts LAUNDRY BEAR will pivot to other webmail platforms as Zimbra patching improves, meaning today's fix addresses one door rather than the group's underlying capability.