Laundry Bear is a Russian state-supported cyberespionage actor active since at least 2024, also tracked as Void Blizzard, TA488, UAC-0190, CL-STA-1114, and formerly UNK_PitStop. Its operations involve private contractors working for Russian intelligence and focus on collecting sensitive communications and files from Western governments and commercial organizations, including targets in the United States and Ukraine. Targeted sectors include government, military and defense, energy and nuclear, research and education, technology, telecommunications, financial services, hospitality, aerospace, media, and civil society. The actor compromises cloud and webmail environments through password spraying, credential phishing, stolen session-cookie and token replay, and exploitation of email-rendering vulnerabilities. It uses living-off-the-land techniques and geographically proximate proxies to evade access restrictions. Beginning by July 2025, Laundry Bear exploited CVE-2025-66376 in Zimbra Collaboration Suite through malicious HTML emails that execute JavaScript when opened or previewed, without requiring a link click or attachment execution. Its ZimReaper payload steals authentication material and browser-autofill credentials, enumerates organizational address directories, and exports the previous 90 days of email. It establishes persistent mailbox access by creating application-specific passwords that bypass two-factor authentication and uses compromised accounts to distribute additional malicious messages. Payload fragmentation and obfuscation conceal executable content, while DNS tunneling and HTTP transfers support exfiltration. In July 2026, Laundry Bear used CVE-2026-42897 against on-premises Microsoft Exchange Outlook Web Access to deploy OWAReaper, a browser-resident JavaScript implant. OWAReaper harvests saved credentials and OAuth tokens, collects mailbox information, and establishes persistence through browser storage, poisoned offline message caches, and server-side mailbox permission changes. These permission changes can preserve access despite password rotation or endpoint rebuilding. The implant receives commands through GitHub commit messages and specially formatted emails, exfiltrates data over HTTPS through legitimate image-delivery services, and supports DNS-based fallback exfiltration. Its reliance on authenticated browser sessions, legitimate APIs, and server-side access mechanisms reduces dependence on conventional endpoint malware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376.
CVE-2026-42897 is described as a high-severity (CVSS 8.1) stored XSS vulnerability in on-premises Microsoft Exchange Server Outlook Web Access (OWA). Malicious email HTML is rendered into the authenticated DOM without adequately neutralizing JavaScript event handlers; opening the email in OWA triggers the attack.
220 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Russian-affiliated activity cluster reported to collect large volumes of email and files through cloud access. The article uses this previously reported activity as a comparison supporting its forecast of future state-backed mail-collection disclosures; it does not explicitly attribute the Zimbra campaign to Void Blizzard.
Conducted a sophisticated zero-click espionage campaign against Western government and critical-infrastructure organizations by sending emails containing an exploit for Zimbra Collaboration Suite. Exploitation enabled access to webmail servers and user mailboxes, persistence, theft of sensitive emails and authentication data, and subsequent targeted spear-phishing.
Campagne d’espionnage et de compromission persistante de boîtes aux lettres Microsoft Exchange on-premises. Le groupe exploite CVE-2026-42897 dans Outlook Web Access pour déployer l’implant JavaScript OWAReaper, récolter identifiants, jetons OAuth et données de messagerie, maintenir des droits Exchange persistants, puis exfiltrer les données via HTTPS/CDN ou tunneling DNS.
Conducting zero-click email espionage campaigns that exploit webmail vulnerabilities to steal email correspondence, session tokens, and credentials from critical-sector organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.