Russian state-backed actors tracked as Laundry Bear, TA488, and Void Blizzard have conducted zero-click phishing campaigns exploiting CVE-2025-66376 in Zimbra Collaboration Suite webmail deployments. Crafted emails can trigger malicious code execution merely when viewed on vulnerable systems, enabling theft of email correspondence, session tokens, and credentials without requiring a victim to open a link or attachment. Reported targets include Ukrainian government bodies and U.S. defense, nuclear, and research organizations, alongside government, telecommunications, finance, and aerospace entities.
Azerbaijan’s National Cybersecurity Agency warned that Zimbra users have faced these campaigns since July 2025 and that compromised systems could expose sensitive mail data, allow unauthorized account access, and support follow-on intrusions. Organizations should apply Zimbra security updates, monitor for anomalous logins and account changes, revoke active sessions and investigate suspected compromise, preserve backups, and reinforce phishing and social-engineering awareness.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Phishing campaigns targeting organizations using Zimbra Collaboration Suite began in July 2025. The campaigns used crafted emails exploiting CVE-2025-66376, where viewing a message on a vulnerable system could enable malicious-code execution.
Azerbaijan’s National Cybersecurity Agency issued an alert about targeted threats to Zimbra Collaboration Suite users and advised organizations to apply updates for CVE-2025-66376, monitor for suspicious activity, revoke sessions when needed, and investigate suspected compromises.
The UK National Cyber Security Centre issued an advisory concerning the reported zero-click webmail attacks.
The threat actors later adapted their operations to exploit a second, unspecified vulnerability in Outlook Web Access.
The activity, attributed to Laundry Bear (TA488/Void Blizzard), targeted Ukrainian government entities and U.S. defense, nuclear, and research organizations, as well as government, telecommunications, finance, and aerospace sectors. Attackers reportedly stole email correspondence, session tokens, and credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.