NCSC issues alert over 'zero-click' phishing campaign hitting enterprises
Ukrainian organizations were used to test new zero-click techniques employed by Russian hackers
The UK’s National Cyber Security Centre (NCSC) has issued an alert over a new ‘zero-click’ threat campaign being waged by Russian state-backed hackers.
The advisory, published in collaboration with international partners, warned ‘beehive’ attacks by the ‘Laundry Bear’ threat group aim to steal email correspondence at organizations operating across a range of critical sectors.
This includes organizations in the defense, education, energy, and technology industries, as well as law enforcement and government agencies.
Attacks against these organizations all have a common theme, according to the NCSC, mainly the use of Zimbra Collaboration Suite (ZCS) software. Targeting focuses specifically on those using vulnerable versions of the software, the advisory noted.
Rather than requiring users to click a link or open a file, zero-click attacks mean users only have to view a malicious email to be compromised.
The NCSC urged organisations that use ZCS to follow mitigation advice, patch immediately, and “improve network monitoring capabilities”.
Crucially, analysis of the campaign found these techniques could be adapted to exploit vulnerabilities in other email software applications used by Western organizations.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
“This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations,” said NCSC chief operating officer (COO) Beth Hopkins.
Ukrainian organizations used in testing
According to the NCSC, the techniques used by Laundry Bear were “extensively trialled” on Ukrainian victims before use against other Western nations. The security agency noted this is part of a growing trend among Russian threat groups.
Notably, technical analysis of the campaign also highlighted the use of AI in development of a “simple codebase” used during operations.
Zero-click attacks have surged in frequency over the last 12 months, research shows, with threat actors accelerating efforts to capitalize on vulnerabilities.
Analysis from Rapid7 found that vulnerability exploitation has now surpassed social engineering as the “largest initial access vector”, accounting for more than one-third (38%) of all attacks.
More than 50% of all exploited vulnerabilities involved zero-click attacks, rather than network-facing vulnerabilities, the study noted, highlighting evolving techniques by threat actors.
“These types of vulnerabilities require no authentication and no user interaction, giving attackers rapid pathways into exposed systems and edge infrastructure,” Rapid7 noted.
Dray Agha, senior manager of security operations at Huntress, said these types of exploits are a “worst-case scenario for defenders” as potential victims are only required to view malicious emails.
“Simply viewing the email in a vulnerable client triggers the compromise,” he explained. “This completely bypasses traditional employee security training and gives state-backed hackers a silent, invisible backdoor into sensitive communications without the victim ever making a mistake.”
Agha said the rise of these techniques mean organizations need to place a greater focus on regular patching to avoid falling prey.
“This is why defense-in-depth is advised, as where the human security layer is porous, the technical defensive layer can step in,” he said.
“Organizations shouldn’t just rely on their staff acting as a ‘human firewall’. Rapid software patching, coupled with layered technical defenses, is the only reliable safety net against modern state-sponsored threats.”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
MSI Prestige 13 AI+ reviewReviews The new MSI Prestige 13 AI+ is every bit as impressive as its big brother, the Prestige 16 AI+, only a lot smaller and a lot lighter
-
AMD expands its software stack with Rocm.aiThe company wants to simplify AI workload deployment with unified development and optimization platform
-
Cisco sounds alarm over new Russian malware campaign hitting firms in US and EuropeNews UAT-11795 is weaponizing legitimate software such as WebEx and Zoom to dupe victims
-
NCSC issues warning over Russian intelligence-backed threat groupNews The advisory comes as the government cracks down on groups involved in “destructive cyber and hybrid operations”
-
Multi-channel phishing attacks: How to manage the riskIn-depth Attackers are evolving beyond email towards phishing across multiple channels. Why is this, and what can be done to manage the risk?
-
UK’s Cyber Resilience Pledge gathers momentum as 60 firms sign up to bolster capabilitiesNews The voluntary pledge sees organizations tightening up their defences, particularly against supply-chain attacks
-
‘The risk to every organization has increased exponentially’: The FortiBleed campaign just took a turn for the worseNews Reports suggest that FortiBleed-linked exposed credentials could put UK government and public services at huge risk
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
Opera browser thinks it has the solution to stopping ClickFix malware attacksNews The browser company is targeting a growing source of malicious links with its new Paste Protect feature
-
US offers $10m bounty for info on Russia-linked hackers behind Signal and WhatsApp attacksNews UNC5792 and UNC4221 have been targeting government officials through their Signal and WhatsApp accounts