CVE Tools
Back to feed
Exploited in the wild Zimbra Collaboration Suite Void Blizzard phishing Cortex Advanced Email Security Zimbra

Russian Global Webmail Espionage

Palo Alto Unit 42·By Unit 42··4 min read
CVE Tools coverage

Unit 42 has uncovered a sustained espionage campaign attributed to Russian threat groups Void Blizzard and LAUNDRY BEAR, exploiting a critical vulnerability in Zimbra Collaboration Suite (CVE-2025-66376). Attackers used zero-click phishing emails to inject malicious JavaScript payloads into unpatched systems, stealing login credentials, email archives, and search histories. The flaw is being actively exploited against government, defense, and financial organizations in NATO countries, Ukraine, CIS nations, and parts of Africa. Palo Alto Networks recommends updating Zimbra and leveraging Cortex Advanced Email Security to mitigate risks.

Executive Summary

Unit 42 has observed a persistent cyberespionage campaign we track as CL-STA-1114. This activity cluster overlaps with activity from a Russian threat actor tracked by other vendors as Void Blizzard and LAUNDRY BEAR.

The attackers behind this campaign targeted Zimbra webmail in organizations in the following sectors:…

Continue reading on Palo Alto Unit 42