
LAUNDRY BEAR
LAUNDRY BEAR is a Russian state-supported cyber actor, also tracked as Void Blizzard, CL-STA-1114, TA488 and UNK_PitStop.
LAUNDRY BEAR is the Russian state-linked group that CISA, the NSA and FBI led 15 nations in naming on 23 July 2026 over a zero-click Zimbra webmail flaw exploited for up to 90 days.
Last refreshed: 3 August 2026 · Appears in 1 active topic
LAUNDRY BEAR needs no click to steal your mail, so what happens once Zimbra finally patches?
Timeline for LAUNDRY BEAR
Mentioned in: One firm hedged, heise online named APT28
Cybersecurity: Threats and DefencesRan a zero-click exploit chain against Zimbra webmail
Cybersecurity: Threats and Defences: Zimbra preview leaks mail to RussiaBackground
LAUNDRY BEAR is a Russian state-supported cyber actor also tracked under the aliases Void Blizzard, CL-STA-1114, TA488 and UNK_PitStop, reflecting the industry's common practice of different vendors assigning separate names to overlapping activity before attribution converges.
On 23 July 2026, CISA, the NSA and FBI led a Coalition of 15 nations in publicly naming the group over its exploitation of a zero-click flaw in Zimbra webmail, which let it read victims' email for up to 90 days without requiring any click from the target. A patch for the underlying flaw had existed for eight months before the public warning was issued.
The group is tracked separately from FSB Centre 16, which the UK's NCSC and 18 partner agencies attributed a distinct router-hijacking campaign to on 9 July 2026; the two are not established as the same actor in current reporting.