Russian state-supported cyber actors conduct phishing campaign targeting users of Zimbra Collaboration Suite
A group of Russian state-supported cyber actors has been targeting and compromising
various Western government and commercial organizations using the Zimbra
Collaboration Suite (ZCS) software since at least July 2025.
The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the
cybersecurity community under several names, primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD).
LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the
Russian Federation, with these actors primarily focusing on the covert acquisition of
email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated
initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest
campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first
exploited and continues to be successfully exploited. The vulnerability, Common
Vulnerabilities and Exposures (CVE) CVE-2025-66376, was patched in November 2025.
Read more at IC3