Palo Alto Networks Unit 42 reported that a cyberespionage campaign tracked as CL-STA-1114, overlapping with activity attributed by other vendors to Void Blizzard and LAUNDRY BEAR, has been exploiting Zimbra Collaboration Suite webmail servers at government, defense, transportation, and financial organizations. The activity has affected targets across NATO member states, Ukraine, CIS countries, and Africa, with researchers saying the broader cluster has been active since at least 2024 and Zimbra-focused operations began in July 2025.
The attackers used zero-click phishing emails to exploit CVE-2025-66376 in Zimbra webmail, allowing a malicious JavaScript payload to run in victims’ browsers without user interaction. Unit 42 said the malware can steal Zimbra credentials, CSRF tokens, 2FA scratch codes, system details, and up to 90 days of email and search history. Researchers also identified at least nine IP addresses and nine domains tied to command-and-control infrastructure, with servers remaining active for an average of 35.4 days, and warned that unpatched Zimbra instances are being actively targeted.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The campaign used zero-click phishing emails exploiting CVE-2025-66376 in Zimbra webmail to inject malicious JavaScript into victims’ browsers without user interaction. The payload exfiltrated credentials, CSRF tokens, 2FA scratch codes, system details, and up to 90 days of email and search history.
Unit 42 said the campaign targeting Zimbra Collaboration Suite webmail began in July 2025. The operation targeted organizations in government, defense, transportation, and finance across NATO member states, Ukraine, CIS countries, and Africa.
Unit 42 reported that the broader cyberespionage activity cluster tracked as CL-STA-1114 has been active since at least 2024. The activity overlaps with reporting by other vendors on the Russian threat actor Void Blizzard, also known as LAUNDRY BEAR.
On 2026-07-23, a joint alert from 27 US, UK, and other international government agencies warned that Russia-linked Laundry Bear/Void Blizzard had exploited CVE-2025-66376 in Zimbra since at least July 2025. The alert said the zero-click campaign targeted Western organizations across government, defense, education, energy, law enforcement, media, NGO, and technology sectors and advised reviewing published IOCs and minimizing Zimbra webmail use until patched.
On 2026-07-23, the UK NCSC and partners from 15 countries disclosed and attributed a zero-click phishing campaign against vulnerable Zimbra webmail instances to the Russian state-supported group LAUNDRY BEAR. The advisory said the espionage activity had been stealing sensitive email data since July 2025 and urged organizations to patch Zimbra systems and improve monitoring.
On 2026-07-23, Unit 42 publicly described the persistent cyberespionage campaign tracked as CL-STA-1114 and documented its overlap with activity attributed by other vendors to Void Blizzard/LAUNDRY BEAR. The report also noted at least nine IP addresses and nine domains used as command-and-control infrastructure and said attackers were actively targeting unpatched Zimbra instances.
CISA said Laundry Bear exploited CVE-2025-66376 as a zero-day before Zimbra patched the cross-site scripting flaw in November 2025. The vulnerability allowed crafted HTML emails in Zimbra Classic UI to execute JavaScript automatically and steal account data.
On 2026-03-18, CISA added CVE-2025-66376 to its Known Exploited Vulnerabilities catalog after reporting that the Zimbra flaw had been exploited in the wild. The vulnerability had been used in a Russian espionage campaign targeting webmail users.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecyberscoop.com
Open sourcemalware.news
Open sourcenextgov.com
Open sourceseqrite.com
Open sourcecve.org
Open sourceic3.gov
Open sourcemedia.defense.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.