Ulej is a custom-developed email-compromise and data-exfiltration capability used by the Russian state-sponsored threat actor LAUNDRY BEAR, also tracked as Void Blizzard, CL-STA-1114, and TA488. It has been used since at least July 2025 in espionage operations targeting organizations running vulnerable Zimbra Collaboration Suite webmail, including entities in government, defense, education, energy, law enforcement, media, non-governmental, and technology sectors.
Ulej exploits CVE-2025-66376, a cross-site scripting flaw in Zimbra webmail, through a view-based, effectively zero-click mechanism. The malicious payload is embedded in a crafted email and executes when the victim merely views the message in a vulnerable webmail client. Reported implementations used obfuscated JavaScript concealed within an SVG element and protected with Base64 encoding and XOR encryption to hinder detection and signature-based blocking.
Once executed in the victim's authenticated browser session, Ulej uses Zimbra webmail functionality and SOAP requests to collect and exfiltrate sensitive mailbox and account data. Documented collection includes the victim’s recent email history, email address, password, Global Address List contents, two-factor authentication recovery material, application passcodes, device and environment details, and OAuth-related account information. The capability has also been observed attempting to coerce browser password managers into autofilling hidden fields to harvest stored credentials.
Ulej supports persistence by enabling IMAP access on compromised mailboxes and creating application-specific passwords that can allow continued mailbox access outside the browser session. Exfiltration has been observed over both HTTPS and DNS, with supporting attacker infrastructure referred to as Flowerbed and Catcher handling receipt and temporary storage of stolen data. The operation reflects a focused espionage objective centered on covert acquisition of organizational email and account data from Zimbra environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The actors leverage a view-based exploit that triggers automatically when a user views a malicious email within a vulnerable version of the webmail service. This exploited a zero-day vulnerability (CVE-2025-66376) when it was first used by the threat group and is still used to successfully exploit ZCS instances that are still unpatched. | Supported by a custom-developed capability named “Ulej,” the actors leverage a view-based exploit that triggers automatically when a user views a malicious email within a vulnerable version of the webmail service.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Supported by a custom-developed capability named “Ulej,” the actors leverage a view-based exploit that triggers automatically when a user views a malicious email within a vulnerable version of the webmail service.
Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise... Using a custom-developed capability named “Улей” or “Ulej” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
It exfiltrates emails and other sensitive user data from a victim’s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [T1074.002] running LAUNDRY BEAR’s “Flowerbed” collection framework.
The exploit attempts to exfiltrate the organization’s email directory, the last 90 days of the victim’s communications, and other sensitive information to servers controlled by the actors.
L’exfiltration utilise deux canaux : DNS ... et HTTPS
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware/tool developed by LAUNDRY BEAR to exploit Zimbra XSS vulnerability CVE-2025-66376 via obfuscated JavaScript in malicious emails, execute on message view without user click, and exfiltrate mailbox contents, credentials, GAL data, 2FA tokens, and application passcodes.
Custom-developed aggregation and data exfiltration malware used by Laundry Bear in a zero-click Zimbra campaign. It executes via malicious JavaScript in HTML email, performs reconnaissance, steals credentials and mailbox data, enables IMAP persistence, harvests 2FA codes and saved browser passwords, and exfiltrates collected data over HTTPS and DNS.
A JavaScript-based espionage capability used in a Zimbra zero-day campaign to collect mailbox and account data, enable IMAP, create a Zimbra application passcode, steal credentials, and exfiltrate emails and related data over DNS and HTTPS.
A custom-developed exploit capability used in phishing campaigns against Zimbra Collaboration Suite to automatically trigger when a victim views a malicious email, enabling exploitation of vulnerable ZCS instances and exfiltration of email directories, recent communications, and other sensitive data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.