logo

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

ID: 6428111f-e4e9-502e-ade3-0f9804afd010

STIX ID: report--6428111f-e4e9-502e-ade3-0f9804afd010

Feed Name: CISA Cybersecurity Advisories

Threat Score
92/100

Date Published: 2026-07-21

Date Updated: 2026-07-23

Author: CISA

...
...

## Executive summary A joint advisory details a Russian state‑supported APT (LAUNDRY BEAR / Void Blizzard / TA488) that exploited a zero‑day XSS in Zimbra (CVE-2025-66376) to run a view‑based JavaScript payload (Ulej) which collected and exfiltrated up to 90 days of email, GAL entries, credentials, 2FA scratch codes and app‑specific passwords to actor‑controlled infrastructure (Flowerbed/Catcher) via DNS and HTTPS; the advisory includes IoCs, detection guidance, and mitigation and remediation recommendations including urgent patching, monitoring, and credential resets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.