Also known as: Void Blizzard, Laundry Bear, tracked as, CL-STA-1114, Void, tracked as CVE-2025-66376, CVE-2025-66376
TA488 (Void Blizzard / Laundry Bear) is a sophisticated Russian‑state supported threat actor that has focused on high‑value government, defense, energy and education sectors worldwide, with a pronounced emphasis on U.S. nuclear research facilities and Ukrainian state institutions. In late 2025 the group leveraged an undisclosed cross‑site scripting (CVE‑2025‑66376) vulnerability in Zimbra Collaboration Suite to launch zero‑click "half‑click" attacks that automatically triggered when users previewed malicious emails, obviating any explicit user interaction. The campaign hinged on a blend of social engineering—phishing campaigns engineered to deliver the Ulej-based exploit tool—and client‑side code execution. Once inside a target mailbox, TA488 deployed the ZimReaper malware backdoor, occasionally augmenting it with MATCHBOIL.V2 or SpyPress payloads. This compromise enabled extensive data collection: bulk email exports in TGZ format, extraction of Zimbra Global Address Lists via brute‑force queries, and capture of passwords, app‑specific tokens and two‑factor authentication codes directly from browser sessions. Exfiltration was carried out over covert channels—DNS tunneling using Base32–encoded payloads embedded in TLS SNI fields, as well as HTTP POSTs to command‑and‑control servers hosted on Cloudflare‑spoofed telemetry domains. Persistence mechanisms included creation of app‑specific Zimbra passwords and stealth delivery of obfuscated JavaScript backdoors via deceptive plugin prompts. Following the public disclosure of CVE‑2025‑66376 by Seqrite in February 2026, TA488 appears to have dismantled or shifted its infrastructure, suggesting a tactical pause while the actors re‑evaluate their operational footprint.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TA488, also known as Void Blizzard or Laundry Bear, is a Russian‑aligned espionage group that exploited a zero‑day XSS vulnerability (CVE‑2025‑66376) in Zimbra mail servers to launch half‑click attacks targeting U.S. nuclear, defense and Ukrainian government entities. The actors used client‑side execution, ZimReaper and other backdoors to harvest emails, credentials and MFA codes, exfiltrating data via DNS tunneling and HTTP uploads. The campaign operated for several months in 2025–2026 before the public disclosure of the vulnerability.
Goals & Targeting
TA488’s strategic objectives center on intelligence gathering for Russian geopolitical interests. By compromising mail systems of U.S. nuclear research institutions and defense contractors, the actor seeks privileged access to sensitive scientific data, insider communications and supply‑chain vulnerabilities. The focus on Ukrainian government entities coincides with broader information operations aimed at destabilizing regional security and supporting Russia’s strategic aims in Eastern Europe.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The TA488 campaign spanned roughly five months in 2025, focused initially on Ukrainian government entities before expanding to U.S. nuclear facilities and defense contractors. The actor leveraged the half‑click CVE‑2025‑66376 exploit to gain initial access via view‑based phishing messages, rapidly establishing persistence with ZimReaper-like backdoors. Data exfiltration relied heavily on DNS tunneling and HTTP POSTs of TGZ archives, often masquerading under Cloudflare‑hosted telemetry domains. After the vulnerability was publicly disclosed in February 2026, the group appears to have paused or re‑engineered its infrastructure, indicating a close link between operational tempo and zero‑day availability.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is of high confidence owing to corroborated reports from multiple independent vendors (Proofpoint, CISA, Securitas, Mallory.ai) and public advisories that detail the technical footprint, campaign timeline and targeted sectors. Still, gaps remain regarding the internal organizational structure, precise attribution depth beyond state sponsorship, and long‑term future intent post‑vulnerability disclosure.
No campaigns linked yet.
No observed data linked yet.
4
Techniques
42
Tools
0
Campaigns
40
IOCs
0
Observed Data
4
Tactics