Back to Feed
Threat IntelligenceJul 23, 2026

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

Russian state-sponsored actors exploit Zimbra Collaboration Suite via zero-day vulnerability.

Summary

Russian state-sponsored APT group LAUNDRY BEAR is targeting organizations using Zimbra Collaboration Suite (ZCS) with a novel exploit for CVE-2025-66376. This zero-day vulnerability, patched in November 2025, allows attackers to exfiltrate emails, the Global Address List, and other sensitive data by simply viewing a malicious email. The campaign, active since July 2025, aims to gather intelligence for the Russian Federation.

Full text

Cybersecurity Advisory Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Release DateJuly 23, 2026 Alert CodeAA26-204A Related topics: Cyber Threats and Response Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [1]. LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) CVE-2025-66376, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities. Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the Persistence and credential access section. This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies: United States National Security Agency (NSA) United States Federal Bureau of Investigation (FBI) Netherlands Defence Intelligence and Security Service (MIVD) Netherlands General Intelligence and Security Service (AIVD) United States Cybersecurity and Infrastructure Security Agency (CISA) United States Defense Counterintelligence and Security Agency (DCSA) United States Department of Defense Cyber Crime Center (DC3) United States Department of the Treasury United States Naval Criminal Investigative Service (NCIS) Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre) New Zealand National Cyber Security Centre (NCSC-NZ) United Kingdom National Cyber Security Centre (NCSC-UK) Czech Republic National Cyber and Information Security Agency (NÚKIB)1 Danish Defence Intelligence Service (DDIS)2 Estonian Foreign Intelligence Service (EFIS)3 Finnish Defence Intelligence (FDI)4 Finnish Security and Intelligence Service (SUPO)5 French General Directorate for Internal Security (DGSI)6 French National Cybersecurity Agency (ANSSI)7 Italian External Intelligence and Security Agency (AISE)8 Italian Internal Intelligence and Security Agency (AISI)9 Security and Intelligence Service of the Republic of Moldova (SIS RM)10 Polish Foreign Intelligence Agency (AW)11 The Military Counterintelligence Service of Poland (SKW)12 Spain National Intelligence Centre (CNI)13 Sweden National Cyber Security Centre (NCSC-SE)14 The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the Mitigations section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed Indicators of compromise (IOCs). As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity. For a downloadable list of IOCs, see: AA26-204A.stix.xml (STIX XML) AA26-204A.stix.json (STIX JSON) Cybersecurity industry tracking The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community: LAUNDRY BEAR Void Blizzard [2] CL-STA-1114 [3] TA488 (formerly UNK_PitStop) [4] Note: Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings. Background Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [1] [2]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024. The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [T1114.002]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [T1078], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence & Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [T1557]. Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [T1587.001] named

Indicators of Compromise

  • cve — CVE-2025-66376
  • domain — zmailanalytics[.]com
  • domain — zimbra-metadata[.]com
  • domain — analyticemailmeter[.]com
  • domain — emailanalytics.com[.]ua
  • domain — mailnalysis[.]com
  • domain — zimbrastat[.]com
  • domain — zimbrasoft.com[.]ua
  • domain — synacorzimbra[.]nl
  • domain — istc-cloud[.]com
  • email — ivanka.zurabishvili@proton[.]me
  • email — zmul1@buildandconsulting[.]com
  • email — garrysmithme@pinmx[.]net
  • email — hostingclient@pinmx[.]net
  • email — c.laurent.ejfa@proton[.]me
  • email — j.moreau.epsc@proton[.]me
  • email — liberty.insights@proton[.]me
  • domain — isofts.kiev[.]ua
  • domain — navs.edu[.]ua
  • hash_sha256 — 98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf
  • hash_sha256 — 60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874
  • hash_sha256 — b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d
  • hash_sha256 — 1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760
  • ip — 216.252.238[.]104
  • ip — 216.252.238[.]18
  • ip — 37.120.247[.]228
  • ip — 185.86.79[.]95
  • ip — 104.248.134[.]194
  • ip — 64.226.124[.]190
  • ip — 193.238.152[.]66
  • ip — 216.252.238[.]64
  • ip — 194.156.103[.]193

Entities

LAUNDRY BEAR (threat_actor)Void Blizzard (threat_actor)TA488 (threat_actor)Zimbra Collaboration Suite (product)Evilginx (product)Phishing (technology)