تخطي إلى المحتوى الرئيسي
Cyber News Unit 42 3 days ago

Russian Global Webmail Espionage

Un
Unit 42

Executive Summary

Unit 42 has observed a persistent cyberespionage campaign we track as CL-STA-1114. This activity cluster overlaps with activity from a Russian threat actor tracked by other vendors as Void Blizzard and LAUNDRY BEAR.

The attackers behind this campaign targeted Zimbra webmail in organizations in the following sectors:

  • Governments
  • Defense
  • Transportation
  • Financial organizations across the following regions:
    • NATO member states
    • Ukraine
    • Commonwealth of Independent States (CIS) countries
    • Africa

Unique to this campaign, the group leveraged zero-click phishing emails that exploit a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform (CVE-2025-66376). The exploit automatically injects a malicious JavaScript payload without requiring recipient interaction. Once executed, the payload exfiltrates sensitive user data, including login credentials, email archives, and search histories. Threat actors continue to actively target unpatched ZCS instances using CVE-2025-66376.

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team.

Related Unit 42 Topics Cyberespionage, Phishing, Data Exfiltration

View Original Report

This intelligence was aggregated from Unit 42.

Read on Source