Washington, D.C.

Russian Email Trap Has Honolulu on Alert, Feds Warn Zimbra Users

AI Assisted Icon
Published on July 23, 2026
Russian Email Trap Has Honolulu on Alert, Feds Warn Zimbra UsersSource: X/FBI Honolulu

Russia-linked hackers have been quietly raiding inboxes at organizations that rely on the Zimbra Collaboration Suite, and in many cases all it takes is viewing a single booby-trapped email. Once the malicious message is rendered, attackers can siphon off recent mail, address book entries and authentication data without the victim ever clicking a thing. Honolulu’s FBI field office is now boosting that warning to local IT teams and partner agencies.

The threat is laid out in a 31-page joint cybersecurity advisory released July 23, 2026, by U.S. and allied cyber agencies. According to IC3, the Russia-linked operators tracked as LAUNDRY BEAR are exploiting CVE-2025-66376, a stored cross-site scripting bug in Zimbra. Using a custom tool called “Ulej,” the group can harvest up to the last 90 days of email from targeted accounts, pull Global Address List entries and capture authentication tokens. The National Security Agency separately summarized the alert and urged organizations to patch and monitor their mail systems, per NSA.

How the View Exploit Works

Security researchers say the bug lives in Zimbra’s Classic web interface and allows JavaScript that is embedded in HTML emails to execute as soon as the message is displayed. The result is a “zero-click” style attack that sidesteps defenses focused on users clicking malicious links. Technical analysis from The Record describes how the malicious payload is often tucked inside SVG content or HTML attributes, then decoded in the victim’s browser. From there, the code uses the victim’s already-authenticated session to pull mailbox data and send it off to servers controlled by the attackers. Analysts warn the same exploit can try to establish long-term access by creating app-specific passwords or switching on IMAP access inside compromised accounts.

Who Is at Risk

The joint advisory and partner cyber centers report that victims include organizations in defense, federal and local government, education, energy, law enforcement, media, nongovernmental organizations and technology. The group also tested its techniques extensively against Ukrainian targets before broadening its operations, according to NCSC. That mix of targets means both big institutions and smaller organizations that run their own Zimbra servers could be exposed if they have not applied the fixes. Network and mail administrators are being urged to assume that any mailbox which received HTML-heavy email from unknown or even internal-looking sources during the relevant window might need a closer look.

What Organizations Should Do

Agencies are calling for immediate patching to the supported fixed releases of Zimbra, removal of any unexpected app-specific passwords and active threat hunting for indicators such as unusual IMAP activity or newly created Zimbra app passwords. The NSA’s summary stresses that patching stops new exploitation but does not automatically remove any persistence that attackers may have already set up, so potentially affected organizations should review logs, reset credentials and follow the mitigation checklist in the advisory, according to NSA. Additional reporting from BleepingComputer underscores that organizations should not stop at installing patches and should keep hunting for suspicious access patterns or lingering backdoors. The advisory also points administrators toward reporting channels and indicator feeds that can support incident response if compromise is suspected.

Why Honolulu Readers Should Care

The Honolulu FBI field office has pushed the advisory out to local partners and flagged it publicly on X; you can see the post from FBI Honolulu on X and revisit earlier coverage of local cyber alerts in Russian Spies Probing Honolulu Routers. City agencies, universities and local service providers that host email should treat Zimbra patching and mailbox hunting as urgent work. Confirmed or suspected compromises are expected to be reported both to law enforcement and to the Internet Crime Complaint Center, as outlined in IC3.

For local IT teams and everyday users, the message is simple: verify that any Zimbra systems are fully updated, comb through mailbox and authentication logs for odd access patterns, and escalate anything suspicious to your incident response contacts. The advisory includes detailed mitigation steps and indicator lists to help organizations carry that work across the finish line.