logo

Russian-Linked Hackers Target Zimbra Users With Zero-Day Exploit

ID: 1aa572c2-18dd-521b-b9ba-bb566b7b44c9

STIX ID: report--1aa572c2-18dd-521b-b9ba-bb566b7b44c9

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Samiksha Jain

...
...

A joint advisory attributes a view-based phishing campaign exploiting CVE-2025-66376 in Zimbra Collaboration Suite to the Russian state-supported APT LAUNDRY BEAR; the zero-day allowed a JavaScript payload to run when a malicious email was merely viewed, enabling multi-stage collection and exfiltration of up to 90 days of email, credentials, 2FA tokens, GAL data and attachments via custom tools (Ulej) and the Flowerbed exfiltration framework. The activity, active since at least July 2025, targeted government, defense, energy, education, media, NGOs and tech organizations; mitigations include immediate patching, avoiding the Classic ZCS webmail client, revoking application passcodes/2FA scratch keys, and enhanced network and endpoint monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.