Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Summary
Russian state-supported cyber actors, identified as APT group LAUNDRY BEAR, have been targeting organizations using Zimbra Collaboration Suite (ZCS) since at least July 2025. This campaign exploits a novel, previously zero-day vulnerability (CVE-2025-66376) which, once patched, allows the actors to exfiltrate email data and establish persistent access through a view-based exploit.
IFF Assessment
This article details a sophisticated, state-sponsored phishing campaign that exploits a zero-day vulnerability, posing a significant threat to organizations and their sensitive data.
Severity
The vulnerability is exploited via a view-based mechanism requiring only viewing a malicious email, suggesting a low attack complexity. It allows for sensitive data exfiltration and persistence, indicating a high impact.
CISA KEV: Listed as actively exploited. Federal patch due: April 01, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should prioritize patching Zimbra Collaboration Suite to address CVE-2025-66376 and implement additional mitigations to detect and prevent view-based exploits. Awareness of state-sponsored phishing campaigns targeting collaboration platforms is crucial for proactive defense strategies.