Laundry Bear’s webmail hackers had more in store after February, report says
Researchers say the Russian state-linked hacking group tracked as Laundry Bear recently began exploiting a bug in Microsoft Outlook Web Access.
Researchers say the Russian state-linked hacking group tracked as Laundry Bear has been more active in recent months than originally thought.
Government agencies and cybersecurity companies warned on July 23 that the cyber-espionage group was abusing a vulnerability in Zimbra Collaboration Suite’s webmail platform. On Wednesday, researchers at Proofpoint issued an update saying that the same hackers began exploiting a bug in Microsoft Outlook Web Access (OWA) a day before the international alert.
Laundry Bear targeted “US and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors,” the researchers said. The goal, as with the campaign against Zimbra users, was to steal emails and account credentials.
Source: https://therecord.media/russia-hackers-outlook-webmail-malware
Related breach coverage
- US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers2026-07-24
US agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners published a joint advisory to warn that the Russia-linked APT […]
- US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups2026-07-15
US and allies warn of Russian APT groups targeting routers and network devices to compromise critical infrastructure worldwide. The US and allied governments warn that Russian state-sponsored APT groups are scanning and exploiting poorly secured network devices, especially routers, to access critical infrastructure. Groups linked to FSB Center 16, including Berserk Bear, Energetic Bear, Ghost […]
- UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations2026-07-23
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
- International alert spotlights Russia-linked attacks on Zimbra webmail2026-07-23
A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.
