Full Report
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
Analysis Summary
# Threat Actor: LAUNDRY BEAR
## Attribution & Identity
LAUNDRY BEAR is an Advanced Persistent Threat (APT) group identified as being supported by the Russian state. The group is specialized in the covert acquisition of sensitive email data and is linked to Russian intelligence or state-sponsored operations.
## Activity Summary
Since July 2025, LAUNDRY BEAR has been conducting a targeted campaign against Western organizations by exploiting vulnerabilities in email platforms. The campaign is notable for its use of a "zero-click" exploit, which allows for compromise without user interaction. The group notably trialed these methods on Ukrainian victims before expanding operations to target NATO member states.
## Tactics, Techniques & Procedures
- **Zero-Click Exploitation:** Known as **"beehive"** (or **"Ulej"**), this technique exploits vulnerable versions of the Zimbra Collaboration Suite (ZCS).
- **No User Interaction Required:** Unlike traditional phishing, the victim only needs to view the malicious email in their webmail service; no links need to be clicked and no files need to be opened.
- **Persistent Access:** The group focuses on gaining extensive and sustained access to compromised networks to monitor and exfiltrate email data.
- **AI-Enhanced Development:** Technical analysis indicates that Artificial Intelligence (AI) was utilized in the development of the group's exploit code.
- **Trialing/Staging:** The actor uses Ukraine as a testing ground for cyber tools before deploying them against broader Western and NATO targets.
## Targeting
- **Sectors:** Defense, Government, Education, Energy, Law Enforcement, Media, NGOs (Non-Governmental Organizations), and Technology.
- **Geography:** Ukraine (initial testing phase), United Kingdom, United States, and other NATO member countries.
- **Victims:** Specifically organizations utilizing the **Zimbra Collaboration Suite (ZCS)** software.
## Tools & Infrastructure
- **Vulnerable Software:** Zimbra Collaboration Suite (ZCS).
- **Exploit:** "beehive" / "Ulej" zero-click exploit.
- **Infrastructure:** The group leverages malicious emails designed to trigger vulnerabilities upon viewing within the ZCS webmail interface.
## Implications
This campaign represents a significant shift in Russian state-sponsored cyber operations toward more automated, low-interaction exploitation. The use of AI to develop exploits suggests an increasing capability to produce sophisticated tools rapidly. The transition from targeting Ukraine to NATO members indicates a strategic intent to conduct long-term espionage and intelligence gathering against Western political and military infrastructure.
## Mitigations
- **Patch Management:** Immediately update Zimbra Collaboration Suite (ZCS) to the latest version to remediate the "beehive" vulnerability.
- **Network Monitoring:** Enhance monitoring capabilities to detect unusual outbound traffic or unauthorized access to email servers.
- **Early Warning Systems:** UK organizations are encouraged to sign up for the NCSC **Early Warning service** to receive notifications regarding malicious network activity.
- **Zero-Click Awareness:** Security teams should review defenses against zero-click techniques, acknowledging that these exploits may be adapted for other email platforms beyond ZCS.