Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been targeting Western government and commercial organizations using the Zimbra Collaboration Suite software since at least July 2025. The group's primary goal is to gather sensitive information for the Russian Federation, focusing on the covert acquisition of email data. LAUNDRY BEAR's latest campaign uses a novel exploit that was a zero-day vulnerability when first exploited, allowing them to successfully target ZCS users. The vulnerability, CVE-2025-66376, was patched in November 2025, but the group's ability to deploy sophisticated technical capabilities demonstrates their intent to continue targeting ZCS and other email systems. The exploit only requires a user to view a malicious email within a vulnerable version of the webmail service, after which it attempts to exfiltrate the victim's last 90 days of email communications and other sensitive information. The Cybersecurity Advisory warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations. The advisory is being released by multiple authoring and co-sealing agencies, including the US National Security Agency, Federal Bureau of Investigation, and other international partners. LAUNDRY BEAR's targeting is almost certainly to gather sensitive information for the Russian Federation, and their ability to adapt and evolve their tactics, techniques, and procedures makes them a significant threat to Western organizations. The group's use of novel exploits and sophisticated technical capabilities demonstrates their intent to continue targeting ZCS and other email systems, and organizations are urged to regularly update their mail service software and continuously monitor their email systems for malicious activity. The advisory provides recommendations for mitigations and includes specific remediations for organizations to implement if they discover the presence of listed Indicators of compromise.