unit42.paloaltonetworks.com 7/23/2026, 2:20:28 PM · external

Russian hackers exploit Zimbra flaw in zero click email campaign

Russian hackers exploit Zimbra flaw in zero click email campaign
Developing story vulnerability 4 articles tracked
LAUNDRY BEAR Uses CVE-2025-66376 to Hack Zimbra via Phishing
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
🇷🇺 Void Blizzard

UNIT 42 reports on a persistent cyberespionage campaign, tracked as CL-STA-1114, linked to Russian actors known as Void Blizzard and LAUNDRY BEAR. Targeting sectors like government and finance, the attackers exploited a vulnerability in Zimbra webmail (CVE-2025-66376) using zero-click phishing emails that inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials and email archives.

Palo Alto Networks offers protective solutions such as Cortex Advanced Email Security and Advanced URL Filtering to safeguard clients against these threats.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline