1. Executive summary
On 23 July 2026, the UK NCSC and international partners publicly attributed a "zero-click" phishing campaign targeting Western organisations to a Russian state-supported threat group tracked as "LAUNDRY BEAR." The advisory warns that the group is conducting targeted phishing operations using techniques that require no victim interaction to trigger payload delivery. Attribution to LAUNDRY BEAR is unconfirmed in MITRE ATT&CK terms — no MITRE profile exists for this actor in the verified reference data. EMEA financial services are within the broad targeting scope of Western organisations; the bottom-line risk is credential compromise and downstream access to sensitive financial systems via a low-friction initial access vector.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 18: classification of ICT-related incidents and cyber threats | A state-sponsored phishing campaign targeting Western organisations constitutes a relevant cyber threat that firms must classify under their ICT incident taxonomy. | Ensure LAUNDRY BEAR campaign IOCs/TTPs are incorporated into threat classification procedures; classify any successful compromise as a major ICT-related incident if impact thresholds are met. |
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | If a firm is successfully compromised via this zero-click phishing vector, the resulting incident may meet major-incident reporting thresholds. | Pre-stage reporting workflows so that a confirmed LAUNDRY BEAR compromise triggers authority notification within DORA timelines. |
No NIS2 or UK NIS article is specifically engaged beyond general incident-management duties, as the source material does not describe a specific supply-chain failure or OES/RDSP-sector breach.
3. Technical analysis & attack chain
The source material is a single NCSC advisory headline and summary. It confirms the following:
- Threat actor: "LAUNDRY BEAR" — described as Russian state-supported. Attribution is unconfirmed per verified reference data (no MITRE ATT&CK profile exists for this actor). Treat all actor-level claims as single-sourced from the NCSC advisory.
- Attack vector: "Zero-click" phishing campaign. The NCSC describes this as a phishing technique that requires no victim interaction to execute — distinguishing it from conventional phishing that relies on user click-through or credential entry.
- Targeting scope: Western organisations broadly. No sector-specific targeting is described in the available source.
- Attribution partnership: UK NCSC (GCHQ) and international partners are co-attributing.
Confidence caveat: The available source material is limited to the NCSC advisory headline and summary text. No technical detail on the zero-click mechanism, exploited component, CVE, payload, C2 infrastructure, persistence methods, or post-compromise behaviour is available in the provided content. All technical specifics below are absent from the source — this advisory cannot provide attack-chain depth beyond what the NCSC has published. Analysts should obtain the full NCSC advisory and any accompanying partner reports (FBI, CISA, or allied NCSCs) before enforcement actions.
4. Mitigation & containment
Given the absence of technical detail in the source material, the following are general defensive priorities aligned to the confirmed threat description:
P1 — within 24h
- Review the full NCSC advisory at https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign for technical IOCs and TTPs as they are published.
- Alert SOC / threat-intel teams to the LAUNDRY BEAR campaign name and the zero-click phishing vector.
- Ensure email security gateways and endpoint detection platforms are configured to receive any indicator feeds published alongside the advisory.
P2 — within 72h
- Hunt for anomalous inbound email or messaging-platform activity consistent with zero-click exploitation (messages that trigger code execution without user interaction). Specific detection criteria depend on the platform and payload detail not yet available in the source.
- Review authentication logs for suspicious session creation or token issuance following message delivery timestamps.
P3 — within 7 days
- Incorporate LAUNDRY BEAR TTPs (once published in full) into purple-team exercises and phishing simulation programmes.
- Validate that DORA Art. 18 classification procedures can categorise a zero-click phishing compromise under the firm's ICT incident taxonomy.
5. Indicators of compromise
No indicators of compromise available in the source material.
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- UK NCSC (GCHQ), "UK and partners expose Russian state-supported actors for new 'zero-click' phishing campaign targeting Western organisations," https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign, published 2026-07-23.
8. Adverse Trace position
This is a confirmed NCSC-attributed campaign notification from a authoritative national authority, but the available source material is limited to the advisory headline and summary — it contains no technical IOCs, CVEs, payload detail, or post-compromise TTPs. The severity to EMEA financial services is elevated but cannot be precisely scored without the full advisory content. The zero-click phishing vector is significant because it bypasses the human layer of defence entirely, potentially enabling initial access at scale against targeted Western organisations. Attribution to LAUNDRY BEAR is unconfirmed in MITRE terms and single-sourced to the NCSC advisory. Adverse Trace will monitor for the full technical advisory and any accompanying partner publications (CISA, FBI, Five Eyes) and will issue a supplementary advisory with IOCs, detection rules, and concrete containment actions once technical detail is available. Clients should treat this as an awareness-level notification and prepare SOC teams to operationalise follow-on technical guidance.
Published via PulseTrace — Adverse Trace threat intelligence.