Russian-Linked Hackers Target Zimbra Users With Zero-Day Exploit
ID: 1aa572c2-18dd-521b-b9ba-bb566b7b44c9
STIX ID: report--1aa572c2-18dd-521b-b9ba-bb566b7b44c9
Feed Name: The Cyber Express
A joint advisory attributes a view-based phishing campaign exploiting CVE-2025-66376 in Zimbra Collaboration Suite to the Russian state-supported APT LAUNDRY BEAR; the zero-day allowed a JavaScript payload to run when a malicious email was merely viewed, enabling multi-stage collection and exfiltration of up to 90 days of email, credentials, 2FA tokens, GAL data and attachments via custom tools (Ulej) and the Flowerbed exfiltration framework. The activity, active since at least July 2025, targeted government, defense, energy, education, media, NGOs and tech organizations; mitigations include immediate patching, avoiding the Classic ZCS webmail client, revoking application passcodes/2FA scratch keys, and enhanced network and endpoint monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
