Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

Summary

Russian state-supported cyber actors, identified as APT group LAUNDRY BEAR, have been targeting organizations using Zimbra Collaboration Suite (ZCS) since at least July 2025. This campaign exploits a novel, previously zero-day vulnerability (CVE-2025-66376) which, once patched, allows the actors to exfiltrate email data and establish persistent access through a view-based exploit.

IFF Assessment

FOE

This article details a sophisticated, state-sponsored phishing campaign that exploits a zero-day vulnerability, posing a significant threat to organizations and their sensitive data.

Severity

7.2 High

The vulnerability is exploited via a view-based mechanism requiring only viewing a malicious email, suggesting a low attack complexity. It allows for sensitive data exfiltration and persistence, indicating a high impact.

CISA KEV: Listed as actively exploited. Federal patch due: April 01, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching Zimbra Collaboration Suite to address CVE-2025-66376 and implement additional mitigations to detect and prevent view-based exploits. Awareness of state-sponsored phishing campaigns targeting collaboration platforms is crucial for proactive defense strategies.

Read Full Story →