CISA, NSA, FBI and partners warn Zimbra collaboration suite users of ongoing Russian state-supported malicious threat activity
Known primarily as LAUNDRY BEAR, the Russian advanced persistent threat (APT) group’s ongoing covert efforts appear focused on targeting Western government and commercial organizations to gather email data possibly for espionage. A new advisory shares mitigations, indicators of compromise, and remediation to harden networks that use ZCS webmail against this ongoing threat activity.
Unlike traditional phishing that attempts to persuade a user to take an action, such as clicking a link or downloading a file, LAUNDRY BEAR’s current campaign uses a zero-click exploit that only requires a user to view a malicious email within a vulnerable version of the ZCS webmail service.
This campaign uses a custom-developed aggregation and data exfiltration capability called Ulej to exploit a common vulnerabilities and exposures (CVE) in ZCS, CVE-2025-66376, with the potential for adaption to exploit other vulnerabilities as well.