Low Enforcement Guidance us

CISA, NSA, FBI warn of Russian state-supported attacks on Zimbra Collaboration Suite

Original title: CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity

CISA, NSA, FBI and international partners published a joint advisory warning of ongoing Russian state-supported cyber attacks on Zimbra Collaboration Suite (ZCS) users. The advanced persistent threat group LAUNDRY BEAR uses a zero-click exploit requiring only email viewing, deploying a custom tool called Ulej to exploit CVE-2025-66376 and extract sensitive data including email addresses, passwords, and 2FA tokens. Since July 2025, more than 10 organizations across Defense Industrial Base, government, law enforcement, technology, education, media, and NGOs have been successfully targeted. Organizations using ZCS must immediately update vulnerable software and implement the recommended mitigations and remediation actions detailed in the advisory to reduce risk of compromise.

What changed

  • CISA, NSA, and FBI released joint Cybersecurity Advisory on Russian state-supported phishing campaign specifically targeting Zimbra Collaboration Suite users, published July 23, 2026
  • Advisory documents LAUNDRY BEAR APT group's ongoing covert operations using zero-click exploit that requires only viewing malicious email in vulnerable ZCS webmail—no user action needed
  • Custom malicious tool called Ulej identified as capability deployed to exploit CVE-2025-66376 in ZCS, with potential for adaptation to other vulnerabilities
  • Since July 2025, over 10 organizations in Western Defense Industrial Base, federal and local government, law enforcement, technology, education, media, and NGOs have been successfully compromised with exfiltration or attempted exfiltration of email addresses, passwords, and 2FA tokens
  • Advisory provides specific mitigations, indicators of compromise, and remediation actions for organizations using ZCS to harden networks and detect malicious activity

Who is affected

Organizations globally using Zimbra Collaboration Suite webmail, particularly Defense Industrial Base organizations, Western federal and local government agencies, law enforcement, technology companies, educational institutions, media organizations, and NGOs. US jurisdiction advisory from CISA, but threat activity targets international victims.

Language
EN

Frameworks

CISA

Open the original source