Flowerbed is a Python-based, Docker-deployed server-side collection framework used by the Russian state-sponsored espionage actor LAUNDRY BEAR, also tracked as Void Blizzard, CL-STA-1114, and TA488. It supports post-compromise data collection and receipt of exfiltrated information in operations targeting Zimbra Collaboration Suite users, particularly in campaigns exploiting CVE-2025-66376. Flowerbed functions as attacker-controlled receiving infrastructure rather than an endpoint payload, and is designed to ingest, log, and temporarily store stolen victim data delivered over both DNS and HTTPS.
The framework includes multiple coordinated components: Catcher, which acts as the primary HTTP and DNS collection service; Nginx, which fronts the infrastructure as an HTTPS reverse proxy; Certbot, which automates TLS certificate provisioning; and Gardener, which performs health-check and service-monitoring functions. Reported operations used Flowerbed to receive compressed mailbox data, account information, Global Address List contents, credentials, two-factor recovery material, and application passcodes stolen by the related Ulej exploitation capability.
Flowerbed has been associated with cyber-espionage activity against organizations in government, defense, education, energy, law enforcement, media, non-governmental, and technology sectors, with a focus on covert email intelligence collection. In the documented Zimbra campaign, exfiltration to Flowerbed occurred immediately after exploitation and used covert dual channels: smaller data elements were encoded for DNS-based transfer, while larger archives and structured data were uploaded over HTTPS. The infrastructure was operated on attacker-controlled virtual private servers and rotated regularly to reduce exposure and complicate tracking.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-66376 is a stored cross-site scripting vulnerability in the Classic UI of Zimbra Collaboration Suite, creating a path to mailbox theft and abuse of the user’s authenticated webmail session. The flaw was exploited as a zero-day before Zimbra released fixes in November 2025.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Flowerbed est le framework de collecte côté serveur, un projet Python conteneurisé via Docker comprenant : Catcher : serveur DNS/HTTP recevant les données exfiltrées ; Certbot : génération automatique de certificats Let’s Encrypt ; Nginx : reverse proxy HTTPS ; Gardener : health check du service Catcher.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
LAUNDRY BEAR utilise des VPS provisionnés via des identités fictives
Using a custom-developed capability [T1587.001] named “Улей” or “Ulej” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information.
The attack doesn’t require any user interaction other than viewing the malicious email, and once that happens, the attackers get to work exfiltrating a ton of data. This includes the victims’ last 90 days of email communications, email addresses and passwords, the organizations’ email directories such as global address lists, two-factor authentication tokens, and newly created application passcodes.
Evidence details the creation of application passcodes, including passcodes named ZimbraWeb . If an attacker obtains credentials, active session material, application passcodes, or 2FA recovery codes, applying the software patch alone may not remove access that was already established.
The observed campaign reportedly targeted recent email, address-book information, account and mailbox metadata, 2FA recovery material, and application passcode functions.
T1114.002 — Email Collection: Remote Email Collection (Collection)
Smaller data is encoded and transmitted in DNS A-record queries, while larger payloads, including mailbox data, are uploaded over HTTPS as compressed archives to the attacker-controlled servers.
once that happens, the attackers get to work exfiltrating a ton of data
L’exfiltration utilise deux canaux : DNS ... et HTTPS
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Server-side collection framework used in the campaign to receive and manage exfiltrated data over DNS and HTTPS.
A Python-based attacker-side collection and exfiltration system that receives stolen data from Ulej, avoids redundant collection, and supports HTTPS and DNS-based covert data transfer.
A malware collection framework used by Laundry Bear to exfiltrate stolen Zimbra data, including mailbox contents, credentials, GAL data, and 2FA-related tokens, over DNS and HTTPS to actor-controlled infrastructure.
Python- and Docker-based collection/exfiltration framework deployed on actor-controlled VPS infrastructure to receive, aggregate, temporarily store, and facilitate onward transfer of data stolen by Ulej. It includes Catcher, Certbot, Nginx, and Gardener containers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.