Zero-Click: The Attack Your Awareness Training Cannot Reach
Key Intel / TL;DR
  • A Kremlin-backed group known as Laundry Bear spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client, with no click required from the victim.
  • The payload took the last 90 days of mail, the organization's entire email directory, the password saved in the browser, and the codes kept for two-factor authentication.
  • Every phishing awareness program is built on the assumption that a human has to do something. Zero-click removes the action, so there is no decision to train.
  • The controls that work here are patch latency on mail infrastructure, detection of post-exploitation behavior, and cutting what a compromised mailbox can reach.
  • Keep the training. It still covers the attacks that need a click. Add the layer that covers the ones that do not.

Security awareness training rests on a premise almost nobody states out loud: somewhere in the attack, a person has to do something. Click the link. Open the attachment. Enable the macro. Type the password into a page that looks close enough. Every simulated phish, every hover-before-you-click poster, every “report suspicious email” button assumes that a human decision sits between the attacker and the network, and that we can improve the odds on that decision.

This week the US and partner nations published a joint alert about a campaign that removes the decision. A Kremlin-backed espionage group tracked as Laundry Bear spent months inside Western mailboxes by exploiting a then-unknown flaw in Zimbra’s webmail client. Viewing the message was enough. No click, no attachment, no credential page. The user did nothing wrong and the mailbox emptied anyway.

What the Attack Actually Took

The specifics are worth reading closely, because they tell you what the attacker considered valuable and where your own exposure probably sits.

The payload went after four things. The last 90 days of email. The organization’s entire email directory. The password saved in the browser. And the codes kept for two-factor authentication.

Look at that list as an attacker would. The 90 days of mail is the intelligence, the contracts and the disputes and the things people say when they think only a colleague is reading. The directory is the target list, every name and address in the organization, which is what turns one compromised account into a mapped campaign against the rest. The saved browser password and the second-factor codes are the escalation, because together they are enough to sign in somewhere else as that person and pass the check that was supposed to stop exactly that.

That last pairing deserves a moment. A great many organizations put their second factor in the same place as the first. Codes arrive by email, or live in a browser extension, on the same machine, behind the same session. The control was designed on the assumption that an attacker who has the password does not also have the mailbox. A zero-click mailbox compromise collapses that assumption in a single step.

Why Training Has Nothing to Catch Here

I want to be precise about the claim, because “awareness training is dead” is a lazy conclusion and a wrong one.

Awareness training works on a specific class of attack: the ones where the user is the exploit. Credential harvesting pages, business email compromise, invoice fraud, ClickFix-style paste-this-command tricks, malicious attachments. In all of those, the technical control failed or was absent and the human is genuinely the last line. Training moves the numbers there, and the organizations that skip it pay for it.

Zero-click sits outside that class entirely. There is no moment where the user chooses well or badly. The vulnerability is in the software that renders the message, and it fires during the ordinary act of looking at a mailbox. You can run the best-trained workforce in your sector and this campaign works exactly as well against you. Telling that user to be more careful is asking them to perform a decision the attack never offered them.

So the honest framing is narrower than “training is over.” It is that your program has a coverage gap, the gap is the attacks that need nothing from the user, and it can only be closed with controls that sit somewhere other than the human.

Where the Control Actually Lives

Four places, in rough order of what pays off fastest.

Patch latency on the software that renders untrusted content. Your mail server, your webmail client, your browser, your PDF and document viewers, your messaging clients. These are the programs that, by design, take input from strangers and parse it. They are the highest-value targets for a zero-click chain, and they should be on a faster patch clock than the rest of your estate. This is the same reasoning behind treating exposure as a race you cannot win on speed alone, with one important difference. For internet-facing mail infrastructure, patch speed is not optional, because there is no user behavior to fall back on while you wait.

Shrink what the mailbox can reach. A compromised mailbox should not be a skeleton key. Move your second factor off the channel that the mailbox controls: phishing-resistant authenticators and passkeys rather than emailed codes, and hardware-backed where the account matters. Stop letting browsers store passwords for anything that touches production or finance. Restrict who can pull the full email directory, because that export is the difference between one victim and a target list. Each of these is a small change that turns a total compromise into a contained one.

Detect the aftermath instead of the delivery. You are not going to catch the exploit. You can absolutely catch what comes next, because the post-exploitation behavior is loud if you are listening for it. A single account reading and exporting 90 days of mail is anomalous. A directory enumeration is anomalous. A session appearing from an unfamiliar location while the user’s real session continues elsewhere is anomalous. None of these require you to have known about the vulnerability. They require you to have baselined normal mailbox behavior and alerted on the deviation, which is ordinary detection engineering pointed at a system many teams still treat as furniture.

Assume the mailbox is the identity. This is the mental shift that makes the rest of it obvious. For most organizations, the email account is the recovery path for every other account. Password resets land there. Verification codes land there. An attacker who owns the mailbox owns the ability to become that person almost anywhere. If you treat email as a communication tool, you will protect it like one. If you treat it as the root credential it functionally is, you will protect it accordingly, which means tiering it with your most sensitive systems and monitoring it like one.

The Uncomfortable Part for Security Programs

There is a budget conversation buried in this, and it is worth naming.

Awareness training is popular with leadership because it is visible, it produces a metric, and it distributes responsibility across the workforce. Patching your webmail inside a tight window, replacing emailed second factors with hardware keys, and building behavioral detection on mailbox activity are all less visible, harder to schedule, and land on a small technical team that is already busy. The path of least resistance is another training module and a phishing simulation with a better click rate.

That path does nothing about Laundry Bear. A campaign that runs for months against mailboxes worldwide, using a flaw nobody knew about, through the act of looking at an email, is not answered by a higher simulation score. It is answered by whether you patched Zimbra quickly, whether the codes it stole were useful, and whether anyone noticed 90 days of mail leaving.

If you already run a mature program, the useful exercise is to take your control set and sort it by what it assumes about the user. Everything that assumes a decision goes in one pile. Whatever is left is your actual coverage against this class of attack. For a lot of organizations that second pile is thinner than they expect, and this is the same blind spot that shows up in our layered ransomware prevention work: the plan reads well until you remove the step where a human is supposed to intervene.

What To Do This Week

If you run Zimbra, patch it and then work the assumption that the mailboxes were read. Rotate the passwords those browsers had saved, re-enroll two-factor for affected users, and treat your email directory as exposed, which makes every name in it a likely target for the follow-on campaign.

If you do not run Zimbra, the lesson still lands, because the next zero-click will be in something else that parses hostile input. Find those programs in your environment. Put them on your fastest patch track. Get your second factor off the mailbox. Baseline what normal mail access looks like so the abnormal has something to stand out against.

And keep the training. It covers the attacks that need a click, which is still most of them, and the workforce that reports a suspicious message is genuinely worth having. Just stop letting it stand in for the layer underneath, because the attacks that need nothing from your people are the ones your people cannot help you with.

If you want to know which of your systems parse untrusted input, how fast you actually patch them, and what a single compromised mailbox would unlock, that is the work we do. Start with our free Human Attack Surface Score, or contact Grab The Axe and we will map it the way an adversary would.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Author Page →