To the point: Russian state-supported actors are conducting zero-click phishing campaigns against western organizations that require no user interaction.
The UK GCHQ and international partners have uncovered a new phishing campaign by Russian threat group LAUNDRY BEAR. The campaign targets western organizations and employs zero-click techniques for targeted attacks.
The UK National Cyber Security Centre (NCSC) and international partner organizations have issued a coordinated alert regarding a phishing campaign carried out by LAUNDRY BEAR. This group is classified as state-supported by Russia and conducts targeted attacks against organizations in western countries.
The method differs from classical phishing campaigns through the use of zero-click technology. This means that users do not necessarily need to click a link or open a file to become infected. Instead, attackers can compromise systems through mere delivery of messages or content.
For security officers, this means that traditional user awareness approaches alone are insufficient. Technical measures are additionally required: network segmentation, monitoring of suspicious processes, and timely patching of known vulnerabilities. The coordinated alert from the NCSC and its partners is intended to enable organizations to align their detection mechanisms and defensive measures to this specific threat.
Source: www.ncsc.gov.uk · Published 23 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.