CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

Laundry Bear: Russia-Linked Threat Actor Targeting Zimbra Servers

July 23, 2026

Laundry Bear (also known as CL-STA-1114, TA488, UNK_PitStop, Void Blizzard) is a Russia-linked adversary that conducted a phishing campaign against Western government and commercial organizations, exploiting Zimbra vulnerabilities to deploy the ZimReaper payload for email harvesting.