TECH FLOW Svět Androida
← Back to the stream
media.defense.gov · picked by Petr Mišák · 53d ago

Russian state-backed actors target Zimbra email users with phishing campaign

AI summary

Russian state-supported cyber actors from the group LAUNDRY BEAR are conducting a phishing campaign targeting Zimbra Collaboration Suite users. The attackers exploit vulnerability CVE-2025-66376, which allows email exfiltration and account access without requiring user interaction beyond viewing a malicious message in the web client. A consortium of security agencies, including U.S. NSA, FBI, and CISA, as well as Czech NÚKIB, issued the warning.

The summary is written by AI from the source; it isn’t the newsroom’s opinion. For details, read the source.

13 people have already opened the source

Tip author’s note

Email is a highly valuable source of information, enabling attackers to obtain not only compromising materials but also access credentials to other services.

AI questions & answers
What is LAUNDRY BEAR?

LAUNDRY BEAR is a Russian state-supported cyber actor group focused on stealing sensitive information, particularly emails, from Western government and commercial organizations. The group is also known in the security community as Void Blizzard and other designations. It has been active since at least April 2024.

How does the CVE-2025-66376 exploit work?

The vulnerability enables attacks without user interaction—viewing a malicious email in the Zimbra web client is sufficient for the exploit to execute. It automatically exfiltrates the last 90 days of email communications, the organization's email directory, and attempts to establish persistent access to the victim's account.

Which organizations are at risk?

Target organizations are Western government and commercial entities using Zimbra Collaboration Suite. Historically, the group has also targeted Microsoft Exchange users and other email system users.

Questions and answers are written by AI about the topic, not taken from the source; they aren’t the newsroom’s opinion.
Related from the stream
Mentions
  • LAUNDRY BEAR
  • Zimbra Collaboration Suite
  • CVE-2025-66376
  • Void Blizzard
  • NÚKIB
  • NSA
  • FBI
  • CISA
  • Microsoft Exchange
  • Evilginx