Laundry Bear is a Russian state-supported, Russia-aligned cyberespionage threat actor active against Western government and commercial organizations since at least 2024. It is also tracked as Void Blizzard, TA488, UAC-0190, CL-STA-1114, and formerly UNK_PitStop. The group has targeted Ukrainian government entities, U.S. government, defense-industrial, nuclear, and research organizations, and organizations in telecommunications, finance, energy, aerospace, education, technology, media, and civil society. Laundry Bear conducts credential- and mailbox-focused espionage. Its observed access methods include credential phishing, password spraying, stolen-session-token replay, and view-triggered webmail exploitation. In campaigns against Zimbra Collaboration Suite, it exploited CVE-2025-66376 through crafted messages whose malicious content executed when opened or previewed. The group used the ZimReaper JavaScript implant to collect authentication material, directory information, and recent email communications; establish persistent mail access; and exfiltrate data through web and DNS-based channels. The actor later used CVE-2026-42897 against on-premises Microsoft Exchange Outlook Web Access to deploy the browser-resident OWAReaper implant. OWAReaper collects mailbox and client metadata, captures autofilled credentials, steals OAuth access tokens where suitable add-ins are available, and abuses mailbox-folder permissions for server-side persistence that can survive password rotation and endpoint reimaging. It also uses browser storage and offline message caching for persistence, removes exploit artifacts from compromised messages, obtains commands through public web-service content and inbound email, and exfiltrates data via encrypted HTTPS traffic with DNS tunneling as a fallback. Laundry Bear also employs living-off-the-land techniques and uses compromised mailboxes and harvested context for follow-on spearphishing.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The threat group was able to exploit a zero-day XSS vulnerability in the Zimbra Collaboration Suite (CVE-2025-66376), the exploit having been embedded in the HTML body of the message and triggered upon opening or previewing.
CVE-2026-42897 is described as a high-severity (CVSS 8.1) stored XSS vulnerability in on-premises Microsoft Exchange Server Outlook Web Access (OWA). Malicious email HTML is rendered into the authenticated DOM without adequately neutralizing JavaScript event handlers; opening the email in OWA triggers the attack.
220 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a sophisticated zero-click espionage campaign against Western government and critical-infrastructure organizations by sending emails containing an exploit for Zimbra Collaboration Suite. Exploitation enabled access to webmail servers and user mailboxes, persistence, theft of sensitive emails and authentication data, and subsequent targeted spear-phishing.
Campagne d’espionnage et de compromission persistante de boîtes aux lettres Microsoft Exchange on-premises. Le groupe exploite CVE-2026-42897 dans Outlook Web Access pour déployer l’implant JavaScript OWAReaper, récolter identifiants, jetons OAuth et données de messagerie, maintenir des droits Exchange persistants, puis exfiltrer les données via HTTPS/CDN ou tunneling DNS.
Conducting zero-click email espionage campaigns that exploit webmail vulnerabilities to steal email correspondence, session tokens, and credentials from critical-sector organizations.
Conducting zero-click or 'half-click' email espionage campaigns by exploiting webmail vulnerabilities in Zimbra Collaboration Suite and later Outlook Web Access to steal email, session tokens, saved credentials, and OAuth tokens from organizations in critical sectors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.