#laundrybear
Take LaundryBear APT. Microsoft published three domains.

Using body-hash pivots in Synapse, the power-up expanded those seeds into 55 domains + 21 IPs, revealing the campaign’s broader infrastructure.

Enrichment becomes expansion.
November 19, 2025 at 10:15 PM
Russian state-backed LAUNDRY BEAR is exploiting CVE-2025-66376 in Zimbra Collaboration Suite with phishing to steal email data and account details from Western organizations. #Russia #Zimbra #Phishing
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Russian state-supported actors tracked as LAUNDRY BEAR have been exploiting CVE-2025-66376 in Zimbra Collaboration Suite to steal email data and sensitive account information from Western organizations. The campaign uses a view-based phishing exploit, custom tooling called Ulej, and Flowerbed/Catcher infrastructure to collect and exfiltrate data via DNS and HTTPS. #LAUNDRYBEAR #ZimbraCollaborationSuite...
www.hendryadrian.com
July 23, 2026 at 10:00 PM
Russian Laundry Bear cyberspies linked to Dutch Police hack... 👮‍♂️🚨🇳🇱

A previously unknown #Russian-backed #cyberespionage group now tracked as #LaundryBear has been linked to a September 2024 #Dutch #police #security breach! 🕵️‍♂️🔥

#CyberSecurity #tech

www.bleepingcomputer.com/news/securit...
Russian Laundry Bear cyberspies linked to Dutch Police hack
A previously unknown Russian-backed cyberespionage group now tracked as Laundry Bear has been linked to a September 2024 Dutch police security breach.
www.bleepingcomputer.com
May 28, 2025 at 8:03 AM
July 31, 2026 at 1:14 AM
Laundry Bear pivoted to a new exploit days after NCSC warned high-profile Zimbra users. Why do we even bother issuing alerts.

#LaundryBear #PatchingFails
July 30, 2026 at 11:41 AM
A new report reveals Russian group Laundry Bear is using an Exchange OWA zero-day (CVE-2026-42897) and the OWAReaper implant. This isn't just XSS; it's long-term mailbox access that defeats patching and password…

https://www.tpp.blog/ng5ws5c

#cybersecurity #laundrybear #microsoftexchangeowa
July 30, 2026 at 5:17 AM
Russische hackers kapen Exchange-mailboxen via zero-day

Russische hackers misbruiken een zero-day in Exchange Outlook Web Access. Daarmee kapen ze mailboxen van overheden en bedrijven en houden ze langdurig toegang.

#Exchangezero-day #OWAReaper #LaundryBear
Russische hackers kapen Exchange-mailboxen via zero-day - TechNieuwsVandaag.nl
Russische hackers misbruiken een Exchange zero-day in Outlook Web Access. De achterdeur OWAReaper houdt mailboxen open, zelfs na een wachtwoordreset.
technieuwsvandaag.nl
July 30, 2026 at 4:16 AM
Russian hackers are exploiting a new Exchange OWA XSS flaw in half-click email attacks, deploying OWAReaper for long-term mailbox access across U.S. and European government and industry targets. #Russia #Exchange #OWAReaper
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Laundry Bear, also tracked as Void Blizzard and TA488, is using the CVE-2026-42897 Outlook Web Access XSS flaw in half-click email attacks to deliver the OWAReaper backdoor. The campaign targets government and industry organizations across the U.S. and Europe and uses advanced persistence, credential theft, and multi-channel command-and-control to maintain long-term mailbox access. #LaundryBear #VoidBlizzard #TA488 #CVE-2026-42897 #OWAReaper #MicrosoftExchange #OutlookWebAccess
www.hendryadrian.com
July 30, 2026 at 1:45 AM
📰 Peretas Rusia Eksploitasi Celah Zero-Click Zimbra untuk Mencuri Email

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/07/28/peretas-rusia-eksploitasi-zimbra-zero-click-curi-email/

#ber
it#beritaTeknologi2#cve66376 #cyber#cybersecurityl#emaila#keamananSiberd#laundryBearh#phishingo#tekno
July 28, 2026 at 9:51 AM
A critical zero-click exploit in Zimbra webmail allows Russian state-aligned hackers to steal emails and bypass MFA just by opening an email. International agencies issued a joint warning: this persistent threat requires immediate…

https://www.tpp.blog/2ln72nw

#cybersecurity #laundrybear #zimbra
July 24, 2026 at 12:15 PM
🇫🇮 Suojelupoliisi ja sotilastiedustelu varoittavat venäläisen Laundry Bear -kyberuhkatoiminnasta

#NordicNews #Uutiset #LaundryBear #Kyberuhka #Venäjä #Tuoreimmat
Suojelupoliisi ja sotilastiedustelu varoittavat yrityksiä venäläisestä Laundry Bear -kyberuhkatoimijasta
Venäjä on lisännyt kybervakoilua, koska sen perinteisen henkilötiedustelun mahdollisuudet länsimaissa ovat heikentyneet karkotusten ja pakotteiden vuoksi
yle.fi
July 24, 2026 at 7:05 AM
Russian state-backed Laundry Bear is exploiting Zimbra CVE-2025-66376 with malicious HTML emails that auto-run JavaScript, stealing mailboxes and bypassing MFA across government, defense, and other sectors. #Russia #Zimbra #LaundryBear
Russian hackers exploit Zimbra zero-click flaw for email theft
CISA says the Russian state-sponsored group Laundry Bear, also known as Void Blizzard, is targeting Zimbra Collaboration servers with phishing and the now-patched CVE-2025-66376 XSS flaw to steal email data and bypass MFA. The campaign has hit organizations across government, defense, education, energy, media, and NGOs, while exfiltrating stolen information through the group's Flowerbed framework and AiTM phishing kits. #LaundryBear #VoidBlizzard #Zimbra #CVE202566376 #Flowerbed
www.hendryadrian.com
July 24, 2026 at 1:15 AM
De Russische cyberactor Laundry Bear is een nieuwe, maar alarmerende speler op het wereldtoneel van cyberdreigingen.

Podcast Spotify: open.spotify.com/episode/4Mtg...

Podcast Youtube: youtu.be/TIfFZ3RfOq8?...

Artikel Cybercrimeinfo: www.ccinfo.nl/menu-onderwi...

#LaundryBear
Laundry Bear: De Russische cyberdreiging die Nederland en de politie raakt
De Cybercrime Podcast · Episode
open.spotify.com
May 29, 2025 at 10:45 AM
Russian national Denis Nikolayevich Obrezko was charged in a Void Blizzard espionage case. Prosecutors say he helped buy infrastructure used to target U.S. and European organizations and hide activity. #Russia #VoidBlizzard #LaundryBear
Russian national charged in connection with Void Blizzard espionage campaign
Federal prosecutors have charged Russian national Denis Nikolayevich Obrezko with conspiracy to commit unauthorized computer access in connection with a cyber-espionage campaign linked to Void Blizzard, also known as Laundry Bear. Investigators say the group targeted U.S. and European organizations, using stolen session tokens, proxy services, and typosquatted Microsoft domains to steal data and conceal its activity. #VoidBlizzard #LaundryBear #DenisNikolayevichObrezko #MicrosoftEntraID
www.hendryadrian.com
June 11, 2026 at 6:45 PM
Dutch intelligence exposes Russian hacking group 'Laundry Bear' behind cyberattacks on police and NATO. #CyberSecurity #CyberEspionage #LaundryBear #DutchIntelligence #NATO #Russia #CyberThreats thedailytechfeed.com/dutch-intell...
May 27, 2025 at 5:30 PM
🚨 New blog post 🚨

Hunting Laundry Bear: Infrastructure Analysis Guide and Findings

How to enrich previous reporting with Validin to find dozens of indicators not previously reported.

#LaundryBear #VoidBlizzard #APT

www.validin.com/blog/laundry...
Hunting Laundry Bear: Infrastructure Analysis Guide and Findings | Validin
Hunting Laundry Bear: Infrastructure Analysis Guide and Findings
www.validin.com
July 25, 2025 at 12:13 PM