Russian Global Webmail Espionage
Unit 42 has uncovered a sustained espionage campaign attributed to Russian threat groups Void Blizzard and LAUNDRY BEAR, exploiting a critical vulnerability in Zimbra Collaboration Suite (CVE-2025-66376). Attackers used zero-click phishing emails to inject malicious JavaScript payloads into unpatched systems, stealing login credentials, email archives, and search histories. The flaw is being actively exploited against government, defense, and financial organizations in NATO countries, Ukraine, CIS nations, and parts of Africa. Palo Alto Networks recommends updating Zimbra and leveraging Cortex Advanced Email Security to mitigate risks.
Executive Summary
Unit 42 has observed a persistent cyberespionage campaign we track as CL-STA-1114. This activity cluster overlaps with activity from a Russian threat actor tracked by other vendors as Void Blizzard and LAUNDRY BEAR.
The attackers behind this campaign targeted Zimbra webmail in organizations in the following sectors:…