UNIT 42 reports on a persistent cyberespionage campaign, tracked as CL-STA-1114, linked to Russian actors known as Void Blizzard and LAUNDRY BEAR. Targeting sectors like government and finance, the attackers exploited a vulnerability in Zimbra webmail (CVE-2025-66376) using zero-click phishing emails that inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials and email archives.
Palo Alto Networks offers protective solutions such as Cortex Advanced Email Security and Advanced URL Filtering to safeguard clients against these threats.