NCSC issues alert over 'zero-click' phishing campaign hitting enterprises

Ukrainian organizations were used to test new zero-click techniques employed by Russian hackers

Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.
(Image credit: Getty Images)

The UK’s National Cyber Security Centre (NCSC) has issued an alert over a new ‘zero-click’ threat campaign being waged by Russian state-backed hackers.

The advisory, published in collaboration with international partners, warned ‘beehive’ attacks by the ‘Laundry Bear’ threat group aim to steal email correspondence at organizations operating across a range of critical sectors.

This includes organizations in the defense, education, energy, and technology industries, as well as law enforcement and government agencies.

Attacks against these organizations all have a common theme, according to the NCSC, mainly the use of Zimbra Collaboration Suite (ZCS) software. Targeting focuses specifically on those using vulnerable versions of the software, the advisory noted.

Latest Videos From

Rather than requiring users to click a link or open a file, zero-click attacks mean users only have to view a malicious email to be compromised.

The NCSC urged organisations that use ZCS to follow mitigation advice, patch immediately, and “improve network monitoring capabilities”.

Crucially, analysis of the campaign found these techniques could be adapted to exploit vulnerabilities in other email software applications used by Western organizations.

“This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations,” said NCSC chief operating officer (COO) Beth Hopkins.

Ukrainian organizations used in testing

According to the NCSC, the techniques used by Laundry Bear were “extensively trialled” on Ukrainian victims before use against other Western nations. The security agency noted this is part of a growing trend among Russian threat groups.

Notably, technical analysis of the campaign also highlighted the use of AI in development of a “simple codebase” used during operations.

Zero-click attacks have surged in frequency over the last 12 months, research shows, with threat actors accelerating efforts to capitalize on vulnerabilities.

Analysis from Rapid7 found that vulnerability exploitation has now surpassed social engineering as the “largest initial access vector”, accounting for more than one-third (38%) of all attacks.

More than 50% of all exploited vulnerabilities involved zero-click attacks, rather than network-facing vulnerabilities, the study noted, highlighting evolving techniques by threat actors.

“These types of vulnerabilities require no authentication and no user interaction, giving attackers rapid pathways into exposed systems and edge infrastructure,” Rapid7 noted.

Dray Agha, senior manager of security operations at Huntress, said these types of exploits are a “worst-case scenario for defenders” as potential victims are only required to view malicious emails.

“Simply viewing the email in a vulnerable client triggers the compromise,” he explained. “This completely bypasses traditional employee security training and gives state-backed hackers a silent, invisible backdoor into sensitive communications without the victim ever making a mistake.”

Agha said the rise of these techniques mean organizations need to place a greater focus on regular patching to avoid falling prey.

“This is why defense-in-depth is advised, as where the human security layer is porous, the technical defensive layer can step in,” he said.

“Organizations shouldn’t just rely on their staff acting as a ‘human firewall’. Rapid software patching, coupled with layered technical defenses, is the only reliable safety net against modern state-sponsored threats.”

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly
News and Analysis Editor

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.

He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.

For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.