A group of Russian state-supported cyber actors, identified as LAUNDRY BEAR, is conducting phishing campaigns targeting users of the Zimbra Collaboration Suite (ZCS). These activities, ongoing since mid-2025, have exploited a zero-day vulnerability (CVE-2025-66376) to compromise Western government and commercial organizations.
The phishing strategy involves a novel exploit where merely viewing a malicious email can lead to data exfiltration of sensitive information such as the last 90 days of emails and global address lists. CISA and multiple international intelligence agencies have issued warnings urging organizations to patch their systems and adopt security measures to counteract this threat.
The advisory emphasizes the importance of regular software updates, monitoring for suspicious activity, and maintaining security protocols to protect against ongoing and future exploits from this group.