Security Minister Dan Jarvis said Russian state-supported hackers had “tested their methods on victims in Ukraine, before targeting members of NATO”, as the NCSC and 15 partner nations exposed the LAUNDRY BEAR group.

The UK and international partners have exposed a Russian state-supported cyber group for a phishing campaign using a “zero-click” technique to steal emails from Western organisations, the National Cyber Security Centre stated.

The NCSC, part of GCHQ, alongside cyber security agencies in 15 countries, named the group as LAUNDRY BEAR, an advanced persistent threat actor which it says specialises in the covert acquisition of email data. According to the NCSC, the campaign is indicative of espionage and almost certainly carried out with Russian state support.

Since July 2025, the group has targeted and stolen sensitive email information from organisations using the Zimbra Collaboration Suite, according to the advisory. US organisations have been targeted across sectors including defence, government, education, energy, law enforcement, media, NGOs and technology.

The NCSC said the technique, coined “beehive” or “Ulej”, differs from traditional phishing in that it requires no action from the user. Rather than clicking a link or opening a file, a user need only view a malicious email within a vulnerable version of the Zimbra webmail service to be compromised, giving the attackers extensive and sustained access to emails.

Security Minister Dan Jarvis was quoted in the press release as saying: “Today’s action shows we’re working hand-in-hand with our allies to expose Russian state-supported hackers targeting Western organisations. It’s particularly concerning that these thugs tested their methods on victims in Ukraine, before targeting members of NATO. Organisations across the UK should sign up to NCSC’s Early Warning service to ensure they can quickly secure their systems against similar activity.”

Beth Hopkins, NCSC Chief Operating Officer, was quoted in the press release as saying: “The advisory highlights how these malicious cyber techniques were extensively trialled on Ukrainian victims before use against members of NATO, which is part of a growing trend amongst Russian cyber threat groups.” She added that technical analysis indicated artificial intelligence had played a role in developing a simple codebase for the operation.

The agencies caution that the technique could likely be adapted to exploit other vulnerabilities, and that as more organisations update their Zimbra software, the group is very likely to look to target other email systems used by Western organisations. Organisations using the suite are urged to patch vulnerabilities immediately and improve network monitoring, and the NCSC recommends all UK organisations sign up to its free Early Warning service.

The advisory was co-sealed with agencies from Australia, Canada, the Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, Poland, Spain, Sweden, the Netherlands, New Zealand and the United States, and is published on the US National Security Agency website. The naming of LAUNDRY BEAR follows a pattern of coordinated Western attribution of cyber activity to Russian state-linked groups, in which allied agencies jointly publish technical detail to strip an operation of its cover and push potential victims to harden their defences.

George Allison
George Allison is the founder and editor of the UK Defence Journal. He holds a degree in Cyber Security from Glasgow Caledonian University and specialises in naval and cyber security topics. George has appeared on national radio and television to provide commentary on defence and security issues. Twitter: @geoallison

LEAVE A REPLY

Please enter your comment!
Please enter your name here