Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
ID: 6428111f-e4e9-502e-ade3-0f9804afd010
STIX ID: report--6428111f-e4e9-502e-ade3-0f9804afd010
Feed Name: CISA Cybersecurity Advisories
## Executive summary A joint advisory details a Russian state‑supported APT (LAUNDRY BEAR / Void Blizzard / TA488) that exploited a zero‑day XSS in Zimbra (CVE-2025-66376) to run a view‑based JavaScript payload (Ulej) which collected and exfiltrated up to 90 days of email, GAL entries, credentials, 2FA scratch codes and app‑specific passwords to actor‑controlled infrastructure (Flowerbed/Catcher) via DNS and HTTPS; the advisory includes IoCs, detection guidance, and mitigation and remediation recommendations including urgent patching, monitoring, and credential resets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
