Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Executive summary
A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking ), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [ 1 ].
LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) CVE-2025-66376 , was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities.
Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the Persistence and credential access section.
This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies:
United States National Security Agency (NSA)
United States Federal Bureau of Investigation (FBI)
Netherlands Defence Intelligence and Security Service (MIVD)
Netherlands General Intelligence and Security Service (AIVD)
United States Cybersecurity and Infrastructure Security Agency (CISA)
United States Defense Counterintelligence and Security Agency (DCSA)
United States Department of Defense Cyber Crime Center (DC3)
United States Department of the Treasury
United States Naval Criminal Investigative Service (NCIS)
Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)
Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)
New Zealand National Cyber Security Centre (NCSC-NZ)
United Kingdom National Cyber Security Centre (NCSC-UK)
Czech Republic National Cyber and Information Security Agency (NÚKIB) 1
Danish Defence Intelligence Service (DDIS) 2
Estonian Foreign Intelligence Service (EFIS) 3
Finnish Defence Intelligence (FDI) 4
Finnish Security and Intelligence Service (SUPO) 5
French General Directorate for Internal Security (DGSI) 6
French National Cybersecurity Agency (ANSSI) 7
Italian External Intelligence and Security Agency (AISE) 8
Italian Internal Intelligence and Security Agency (AISI) 9
Security and Intelligence Service of the Republic of Moldova (SIS RM) 10
Polish Foreign Intelligence Agency (AW) 11
The Military Counterintelligence Service of Poland (SKW) 12
Spain National Intelligence Centre (CNI) 13
Sweden National Cyber Security Centre (NCSC-SE) 14
The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the Mitigations section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed Indicators of compromise (IOCs).
As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
Read the original article: